PT-2026-93873 · Concrete Cms+1 · Concrete Cms
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Concrete CMS versions prior to 9.5.4
Description
The software re-authorized OAuth REST API requests based solely on the bearer token without verifying the current state of the associated account. The authorization validator only checked if the token existed, was not expired, and had not been explicitly revoked. Consequently, users whose accounts were deactivated, deleted, or locked pending a forced password reset retained full access to the
/ccm/api/1.0/* endpoint for the remaining lifetime of their issued tokens.Recommendations
Update to version 9.5.4 or later.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete Cms