Concrete Cms · Concrete Cms · CVE-2026-85387
**Name of the Vulnerable Software and Affected Versions**
Concrete CMS versions prior to 9.5.4
**Description**
The software re-authorized OAuth REST API requests based solely on the bearer token without verifying the current state of the associated account. The authorization validator only checked if the token existed, was not expired, and had not been explicitly revoked. Consequently, users whose accounts were deactivated, deleted, or locked pending a forced password reset retained full access to the `/ccm/api/1.0/*` endpoint for the remaining lifetime of their issued tokens.
**Recommendations**
Update to version 9.5.4 or later.