Description
Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluating the "Add Message Attachments" permission, which was only checked after the file had been stored. A user denied that permission, or an unauthenticated visitor on a guest-posting configuration, could import approved files of allowed types into the file manager. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Published: 2026-09-15
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized import of files into the CMS file manager
Action: Immediate Upgrade
AI Analysis

Impact

Concrete CMS versions earlier than 9.5.3 contain a missing authorization check that allows files to be stored in the file manager before verifying that the user has the "Add Message Attachments" permission. This flaw permits the upload of approved file types without proper authorization, leading to an unauthorized file import into the CMS’s backend. The vulnerability, defined under CWE‑862 (Missing Authorization), can enable an attacker to introduce files that may be used for data exposure, further exploitation, or persistence within the CMS. The description explicitly states that the permission is only checked after the file is stored, and the CMS security team rated the issue with a low CVSS v4.0 score of 2.3.

Affected Systems

The flaw applies to all Concrete CMS deployments running a version older than 9.5.3. Environments configured to allow guest posting are especially affected because the upload endpoint can be accessed without authentication. Upgrading to version 9.5.3 or later removes the flaw and enforces the permission check before any file is accepted.

Risk and Exploitability

The CVSS v4.0 score of 2.3 indicates a low severity impact, and the EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could reach the upload endpoint over the network, possibly without authentication in guest‑posting settings, and could potentially upload arbitrary files of allowed types. The low attack complexity and low privileged requirement (just lack of the Add Message Attachments permission) mean that exploitation would require minimal effort, but the risk remains moderate in guest‑posting configurations due to the lack of initial authentication.

Generated by OpenCVE AI on September 20, 2026 at 14:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to 9.5.3 or a later patched release that validates the Add Message Attachments permission before accepting uploads
  • Disable guest posting or restrict the conversation attachment upload endpoint to require the Add Message Attachments permission for all users
  • Limit the allowed file types for uploads and enforce file manager permissions through the CMS configuration or custom access controls

Generated by OpenCVE AI on September 20, 2026 at 14:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluating the "Add Message Attachments" permission, which was only checked after the file had been stored. A user denied that permission, or an unauthenticated visitor on a guest-posting configuration, could import approved files of allowed types into the file manager. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.
Title Missing Authorization in Concrete CMS versions below 9.5.3 Conversation File Upload Allows File Import Without the Add Message Attachments Permission
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T19:26:49.254Z

Reserved: 2026-07-30T18:04:50.763Z

Link: CVE-2026-68533

cve-icon Vulnrichment

Updated: 2026-09-15T19:26:43.441Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:37.170

Modified: 2026-09-16T19:16:15.097

Link: CVE-2026-68533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses