Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-87028— Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary Fields

Quick assessment

Affected
Concrete CMS Concrete CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Concrete CMS 9 至 9.5.3 版本未能验证提交到自定义插槽预览端点的 board InstanceItem 是否属于请求用户有权编辑的 board 实例,也未在生成基于页面的摘要内容之前强制执行页面查看权限。因此,拥有单个 board 实例“编辑 board 内容”权限的已认证用户,可以提交一个属于不同 board 实例的项目标识符,并获取该用户本无权查看的底层页面的摘要字段,包括页面标题和描述。 Concrete CMS 安全团队为该漏洞分配的 CVSS v4.0 评分为 5.3,向量字符串为 C

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-87028

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary Fields
Source: CVE Program / CVE List V5
Vulnerability Description
Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting user was authorized to edit, and did not enforce page-view permission before generating page-backed summary content. As a result, an authenticated user holding edit-board-contents permission on a single board instance could submit the identifier of an item belonging to a different board instance and receive summary fields, including the page title and description, of an underlying page the same user was otherwise forbidden to view. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Pakung for reporting.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Concrete CMS Concrete CMS 9.0.0 ~ 9.5.3 -

II. Public POCs for CVE-2026-87028

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-87028

登录查看更多情报信息。

Other References for CVE-2026-87028 (1)

Same Patch Batch · Concrete CMS · 2026-09-16 · 6 CVEs total

CVE-2026-85385 7.7 HIGH Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field
CVE-2026-85386 7.3 HIGH Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticate
CVE-2026-18120 6.3 MEDIUM Missing Authorization in legacy Express entries search endpoint allows disclosure of Expre
CVE-2026-87031 2.1 LOW Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through
CVE-2026-85387 2.0 LOW Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API

IV. Related Vulnerabilities

V. Comments for CVE-2026-87028

No comments yet


Leave a comment