Concrete Cms · Concrete Cms · CVE-2026-87028
**Name of the Vulnerable Software and Affected Versions**
Concrete CMS versions 9 through 9.5.3
**Description**
An authenticated user with `edit-board-contents` permission on a single board instance can access summary fields, such as the page title and description, of pages they are not authorized to view. This occurs because the system fails to verify if a board `InstanceItem` submitted to the 'custom-slot preview' endpoint belongs to the board instance the user is authorized to edit, and it does not enforce page-view permissions before generating page-backed summary content.
**Recommendations**
Update Concrete CMS to a version later than 9.5.3.