CVE-2026-18115: In Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and change_password Enables Account Takeover.

Published Sep 15, 2026
·
Updated

Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edituserproperties permissions on the REST API user write endpoints (PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/changepassword). A user with an update-scoped OAuth token and permission to edit only one non-sensitive field could change another non-superuser's password, username, email, and attributes, taking over that account. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.4 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.

Affected Software

1 affected component
Concrete CMS Concrete CMS>=9.2.0<=9.5.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Concrete CMS to a version that resolves this vulnerability.

    Fixed in 9.5.2
  2. Configuration

    Ensure Concrete CMS enforces per-field edit_user_properties permissions on the REST API user write endpoints: PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/change_password (Missing Authorization in REST API Users update() and change_password).

    Concrete CMS REST API (users update() and change_password) Enforce per-field edit_user_properties permissions on user write endpoints = Enabled

Event History

Sep 15, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
DescriptionWeakness

Frequently Asked Questions

1

Which accounts can be targeted?

An attacker can modify another non-superuser account. The exposed fields include the target account's password, username, email address, and attributes.

2

What access does an attacker need to exploit this?

The attacker needs an OAuth token scoped for user updates and permission to edit at least one non-sensitive user field. They do not need permission for the specific sensitive field they modify.

3

Are superuser accounts affected?

The described authorization bypass applies to other non-superuser accounts. The provided information does not indicate that superuser accounts can be modified through this issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203