CVE-2026-68533: Missing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows File Import Without the Add Message Attachments Permission
Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluating the "Add Message Attachments" permission, which was only checked after the file had been stored. A user denied that permission, or an unauthenticated visitor on a guest-posting configuration, could import approved files of allowed types into the file manager. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Concrete CMSto a version that resolves this vulnerability.Fixed in 9.5.3
Event History
Frequently Asked Questions
Who can exploit this issue?
A user who is denied the "Add Message Attachments" permission can exploit it. On sites configured to allow guest posting, an unauthenticated visitor can also import files.
What conditions are required for exploitation?
The attacker must be able to use the conversation attachment upload endpoint and submit approved files whose types are allowed by the site. The file is imported into the file manager before the attachment permission is evaluated.
Are guest users affected by default?
Unauthenticated exploitation is limited to configurations that permit guest posting. The provided information does not state whether guest posting is enabled by default.
What version resolves the issue?
Concrete CMS 9.5.3 resolves the issue; affected versions are below 9.5.3.