Impact
The vulnerability arises from missing authorization checks on the user update REST endpoints. An attacker holding a valid OAuth token that has update scope can modify fields that the token owner is not permitted to change. By changing a non-superuser account's password, username, email, or attributes, the attacker can fully assume control of the target account. The weakness corresponds to CWE-862.
Affected Systems
Concrete CMS versions 9.2.0 through 9.5.2 are affected. The issue manifests on the REST API endpoints used to update user accounts or change passwords, namely PUT /ccm/api/1.0/users/{uID} and POST /ccm/api/1.0/users/{uID}/change_password. Systems running any of these releases without a subsequent patch are vulnerable.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. Exploitation requires network access and an OAuth token with update scope, but no local privileges are needed. Because the endpoint accepts unauthenticated requests only if the token is present, the attack can be launched remotely. The EPSS score is < 1%, reflecting a low but non‑zero probability of exploitation in the public data set. The vulnerability is not listed in CISA's KEV catalog.
OpenCVE Enrichment