PT-2026-93854 · Concrete Cms+1 · Concrete Cms

·

CVE-2026-87031

·

Published

2026-09-16

·

Updated

2026-09-21

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions 9.2.0 through 9.5.3
Description The REST API user creation endpoint 'POST /ccm/api/1.0/users', specifically the add() function in concrete/src/Api/Controller/Users.php, fails to perform a permission check before creating an account. This allows any valid OAuth token with the users:add scope, including client credentials tokens without an associated user context, to create active and validated user accounts. This process bypasses email verification and administrator approval. With default registration settings, these accounts can edit page content, which may lead to stored cross-site scripting (XSS)—a technique where malicious scripts are permanently stored on a target server—and further system compromise.
Recommendations Update Concrete CMS versions 9.2.0 through 9.5.3 to a version where this issue is resolved. As a temporary workaround, restrict access to the 'POST /ccm/api/1.0/users' endpoint or limit the distribution of OAuth tokens with the users:add scope.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87031

Affected Products

Concrete Cms