PT-2026-92121 · Concrete Cms+1 · Concrete Cms

·

CVE-2026-18110

·

Published

2026-09-15

·

Updated

2026-09-22

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions 9.0.0 through 9.5.2
Description An authorization check is missing on the user selector autocomplete endpoint '/ccm/system/user/autocomplete', which supports the Preview as User panel and other user-selector components. The endpoint only validates a CSRF-style access token bound to display options rather than the caller's identity or permissions. Since this token is issued to anonymous visitors, an unauthenticated attacker can submit an empty search query to trigger a match-all filter. By paginating the results, the attacker can enumerate all backend accounts, disclosing the internal user ID, username, and email address of administrative users, including the super-administrator.
Recommendations Update Concrete CMS versions 9.0.0 through 9.5.2 to a version where this issue is resolved. Restrict access to the '/ccm/system/user/autocomplete' endpoint to minimize the risk of account enumeration.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18110

Affected Products

Concrete Cms