Concrete Cms · Concrete Cms · CVE-2026-18110
**Name of the Vulnerable Software and Affected Versions**
Concrete CMS versions 9.0.0 through 9.5.2
**Description**
An authorization check is missing on the user selector autocomplete endpoint '/ccm/system/user/autocomplete', which supports the Preview as User panel and other user-selector components. The endpoint only validates a CSRF-style access token bound to display options rather than the caller's identity or permissions. Since this token is issued to anonymous visitors, an unauthenticated attacker can submit an empty search query to trigger a match-all filter. By paginating the results, the attacker can enumerate all backend accounts, disclosing the internal user ID, username, and email address of administrative users, including the super-administrator.
**Recommendations**
Update Concrete CMS versions 9.0.0 through 9.5.2 to a version where this issue is resolved.
Restrict access to the '/ccm/system/user/autocomplete' endpoint to minimize the risk of account enumeration.