Description
Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by the normal dashboard and CSV Export flow. An unauthenticated visitor who knew or discovered an Express entity identifier could enumerate that entity's entry search results, disclosing attribute values intended to be restricted to privileged users. For Express entities that do not support entry-specific permissions (i.e., supportsEntrySpecificPermissions() returns false), per-entry permission filtering is additionally disabled via EntryList::ignorePermissions(). The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Daniel Powell for reporting.
Published: 2026-09-16
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of protected Express entry data
Action: Apply patch
AI Analysis

Impact

Concrete CMS before version 9.5.3 contained a legacy Express entry search endpoint that returned full entry result JSON without performing the standard canViewExpressEntries() permission check. This omission allowed an unauthenticated visitor who could guess or learn an Express entity identifier to retrieve sensitive attribute values that should have been restricted to privileged users. The flaw is a classic missing authorization weakness, classified as CWE‑862.

Affected Systems

The vulnerability affects installations of Concrete CMS, Concrete CMS 9.x, that have not been updated to version 9.5.3 or later. Only those versions that retain the legacy Express search API are impacted.

Risk and Exploitability

The CVSS v4.0 score of 6.3 indicates a moderate severity, while the EPSS score of less than 1 % points to a very low likelihood of exploitation today. The flaw is not listed in the CISA KEV catalog. Exploitation requires remote access to the application, knowledge or guess of an Express entity identifier, and does not require authentication. Once accessed, an attacker can enumerate the entry search results for that entity, potentially disclosing confidential data.

Generated by OpenCVE AI on September 18, 2026 at 00:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Concrete CMS to version 9.5.3 or later, which removes the vulnerable legacy endpoint.
  • If an upgrade is not immediately possible, block or disable access to the legacy Express search endpoint in the application configuration or web server.
  • Review and enforce canViewExpressEntries permission checks on any custom or legacy API endpoints to ensure proper authorization.

Generated by OpenCVE AI on September 18, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Fri, 18 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by the normal dashboard and CSV Export flow. An unauthenticated visitor who knew or discovered an Express entity identifier could enumerate that entity's entry search results, disclosing attribute values intended to be restricted to privileged users. For Express entities that do not support entry-specific permissions (i.e., supportsEntrySpecificPermissions() returns false), per-entry permission filtering is additionally disabled via EntryList::ignorePermissions(). The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Daniel Powell for reporting.
Title Missing Authorization in legacy Express entries search endpoint allows disclosure of Express entry data
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-17T17:31:44.663Z

Reserved: 2026-07-28T18:02:03.700Z

Link: CVE-2026-18120

cve-icon Vulnrichment

Updated: 2026-09-17T17:31:40.607Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T18:17:07.970

Modified: 2026-09-21T17:51:22.957

Link: CVE-2026-18120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses