Concrete Cms · Concrete Cms · CVE-2026-18120
**Name of the Vulnerable Software and Affected Versions**
Concrete CMS versions prior to 9.5.3
**Description**
A legacy Express entry search endpoint returns entry result JSON without invoking the `canViewExpressEntries()` permission check. This allows an unauthenticated visitor who possesses an Express entity identifier to enumerate search results and disclose attribute values intended for privileged users. For Express entities where `supportsEntrySpecificPermissions()` returns false, per-entry permission filtering is further disabled through the `EntryList::ignorePermissions()` function.
**Recommendations**
Update to version 9.5.3 or later.