Description
Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates only a CSRF-style access token that is bound to the selector's display options rather than to the caller's identity or permissions, and that token is issued to anonymous visitors because the selector renders without an authorization check. Because an empty query resolves to a match-all filter, an unauthenticated attacker can submit an empty search and paginate the results to enumerate every backend account, disclosing the internal user ID, username, and email address of all administrative users, including the super-administrator (user ID 1). No password hashes or session material are disclosed The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 8.7 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks thirtythree and YesWeHack for reporting.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

Concrete CMS versions 9.0.0 through 9.5.2 have a missing authorization check on the /ccm/system/user/autocomplete endpoint, which is used by user selector components such as Preview as User. This defect corresponds to CWE-862: Missing Authorization Check. The endpoint only verifies a CSRF‑style token that is granted to anonymous visitors, and this token is not tied to the requester's identity or privileges. When an attacker submits an empty query, the endpoint returns all backend user records, revealing internal user IDs, usernames and email addresses. Password hashes or session data are not disclosed, but the exposed account information can be leveraged for further attacks.

Affected Systems

Concrete CMS, versions 9.0.0 through 9.5.2 The vulnerability spans all builds within this version range and applies to any installation that has not yet applied the missing authorization guard to the autocomplete API.

Risk and Exploitability

The CVSS score of 8.7 reflects high impact with low effort to exploit. The vulnerability does not need any special privileges or authentication; an unauthenticated user who can reach the CMS instance can send a request to /ccm/system/user/autocomplete, submit an empty search, and paginate to enumerate every administrative account. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The abuse potential is significant for unpatched installations because the returned data includes all administrator identifiers, which can facilitate credential‑guessing or other malicious actions.

Generated by OpenCVE AI on September 20, 2026 at 15:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to a version that contains the authorization fix for the autocomplete endpoint (e.g., 9.5.3 or later).
  • If an immediate upgrade is not feasible, restrict access to the /ccm/system/user/autocomplete endpoint by using a firewall rule or network ACL that allows only authenticated administrative traffic to reach it.
  • Disable the Preview as User feature or remove any user‑selector UI components that trigger the autocomplete API if they are not required for normal operation.

Generated by OpenCVE AI on September 20, 2026 at 15:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 15 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates only a CSRF-style access token that is bound to the selector's display options rather than to the caller's identity or permissions, and that token is issued to anonymous visitors because the selector renders without an authorization check. Because an empty query resolves to a match-all filter, an unauthenticated attacker can submit an empty search and paginate the results to enumerate every backend account, disclosing the internal user ID, username, and email address of all administrative users, including the super-administrator (user ID 1). No password hashes or session material are disclosed The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 8.7 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks thirtythree and YesWeHack for reporting.
Title Concrete CMS 9.0.0 through 9.5.2 is vulnerable to missing authorization in the user selector autocomplete endpoint (/ccm/system/user/autocomplete), allowing an unauthenticated attacker to retrieve the complete backend user directory — internal ID, username
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-22T18:01:25.063Z

Reserved: 2026-07-28T18:01:11.227Z

Link: CVE-2026-18110

cve-icon Vulnrichment

Updated: 2026-09-22T18:01:19.269Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T17:17:11.110

Modified: 2026-09-22T18:17:11.170

Link: CVE-2026-18110

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:00:14Z

Weaknesses