Description
Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoints (PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/change_password). A user with an update-scoped OAuth token and permission to edit only one non-sensitive field could change another non-superuser's password, username, email, and attributes, taking over that account. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.4 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Published: 2026-09-15
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via unauthorized password change
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises from missing authorization checks on the user update REST endpoints. An attacker holding a valid OAuth token that has update scope can modify fields that the token owner is not permitted to change. By changing a non-superuser account's password, username, email, or attributes, the attacker can fully assume control of the target account. The weakness corresponds to CWE-862.

Affected Systems

Concrete CMS versions 9.2.0 through 9.5.2 are affected. The issue manifests on the REST API endpoints used to update user accounts or change passwords, namely PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/change_password. Systems running any of these releases without a subsequent patch are vulnerable.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity. Exploitation requires network access and an OAuth token with update scope, but no local privileges are needed. Because the endpoint accepts unauthenticated requests only if the token is present, the attack can be launched remotely. The EPSS score is < 1%, reflecting a low but non‑zero probability of exploitation in the public data set. The vulnerability is not listed in CISA's KEV catalog.

Generated by OpenCVE AI on September 20, 2026 at 14:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Concrete CMS release that addresses the missing authorization on user endpoints.
  • Review and limit OAuth token scopes so that only trusted applications receive update permissions.
  • Implement monitoring and rate limiting on the user update endpoints to detect and mitigate anomalous activity.

Generated by OpenCVE AI on September 20, 2026 at 14:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoints (PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/change_password). A user with an update-scoped OAuth token and permission to edit only one non-sensitive field could change another non-superuser's password, username, email, and attributes, taking over that account. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.4 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Title In Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and change_password Enables Account Takeover.
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T19:18:12.049Z

Reserved: 2026-07-28T18:01:58.197Z

Link: CVE-2026-18115

cve-icon Vulnrichment

Updated: 2026-09-15T19:18:07.171Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:17.893

Modified: 2026-09-16T19:16:15.097

Link: CVE-2026-18115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:45:07Z

Weaknesses