PT-2026-93873 · Concrete Cms+1 · Concrete Cms

·

CVE-2026-85387

·

Published

2026-09-16

·

Updated

2026-09-21

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Concrete CMS versions prior to 9.5.4
Description The software re-authorized OAuth REST API requests based solely on the bearer token without verifying the current state of the associated account. The authorization validator only checked if the token existed, was not expired, and had not been explicitly revoked. Consequently, users whose accounts were deactivated, deleted, or locked pending a forced password reset retained full access to the /ccm/api/1.0/* endpoint for the remaining lifetime of their issued tokens.
Recommendations Update to version 9.5.4 or later.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85387

Affected Products

Concrete Cms