Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Polio123

#45057of 57,592
6.5Total CVSS
Vulnerabilities · 1
PT-2026-93853
6.5
2026-09-16
Concrete Cms · Concrete Cms · CVE-2026-87028
**Name of the Vulnerable Software and Affected Versions** Concrete CMS versions 9 through 9.5.3 **Description** An authenticated user with `edit-board-contents` permission on a single board instance can access summary fields, such as the page title and description, of pages they are not authorized to view. This occurs because the system fails to verify if a board `InstanceItem` submitted to the 'custom-slot preview' endpoint belongs to the board instance the user is authorized to edit, and it does not enforce page-view permissions before generating page-backed summary content. **Recommendations** Update Concrete CMS to a version later than 9.5.3.