Description
Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth token with read scope for an Express entity could enumerate entries that its user context lacked permission to view, disclosing each entry's public identifier, URL, label, dates, and any attribute or associated-entry data requested via the includes parameter. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Published: 2026-09-11
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted disclosure of restricted Express entries
Action: Immediate Patch
AI Analysis

Impact

A missing authorization check in the Concrete CMS Express REST API list endpoint allows an attacker in possession of an OAuth token with read scope to enumerate Express entries that the token’s user should not be able to view. The flaw discloses each entry’s public identifier, URL, label, dates, and any attributes or associated-entry data requested via the includes parameter, thereby leaking sensitive or private content. This is an information‑disclosure vulnerability caused by the absence of per‑entry view permission checks.

Affected Systems

Concrete CMS versions 9.2.0 through 9.5.2 are affected. The issue resides in the Express REST API and applies to installations that expose the /Express endpoint and use Express entity.

Risk and Exploitability

The CVSS v4.0 score of EPSS score of less than 1 % shows a low probability of exploitation. The vulnerability is not in the CISA KEV catalog. Remote exploitation is possible over the network through the public REST API, but requires a valid OAuth token with read scope issued to a user. An attacker could enumerate restricted entries and retrieve potentially confidential data.

Generated by OpenCVE AI on September 21, 2026 at 04:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later to apply the vendor fix.
  • Ensure OAuth tokens used for the Express API have the minimal required scope and audit token usage for anomalies.
  • Restrict network access to the /Express REST endpoint or apply IP whitelisting so that only trusted clients can call the endpoint.

Generated by OpenCVE AI on September 21, 2026 at 04:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth token with read scope for an Express entity could enumerate entries that its user context lacked permission to view, disclosing each entry's public identifier, URL, label, dates, and any attribute or associated-entry data requested via the includes parameter. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Title Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-11T19:23:15.759Z

Reserved: 2026-07-28T18:03:19.930Z

Link: CVE-2026-18122

cve-icon Vulnrichment

Updated: 2026-09-11T19:23:11.238Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T18:16:56.567

Modified: 2026-09-11T20:17:12.873

Link: CVE-2026-18122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:30:08Z

Weaknesses