Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Myq

#42052of 57,593
7.1Total CVSS
Vulnerabilities · 1
PT-2026-93873
7.1
2026-09-16
Concrete Cms · Concrete Cms · CVE-2026-85387
**Name of the Vulnerable Software and Affected Versions** Concrete CMS versions prior to 9.5.4 **Description** The software re-authorized OAuth REST API requests based solely on the bearer token without verifying the current state of the associated account. The authorization validator only checked if the token existed, was not expired, and had not been explicitly revoked. Consequently, users whose accounts were deactivated, deleted, or locked pending a forced password reset retained full access to the `/ccm/api/1.0/*` endpoint for the remaining lifetime of their issued tokens. **Recommendations** Update to version 9.5.4 or later.