Description
Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditionally returns true, so no per-object (tree node) authorization is enforced when the group collection is returned. An authenticated user whose API token carries the groups:read scope can call GET /ccm/api/1.0/groups and receive every group on the site regardless of the view permissions on those groups, disclosing the organization's group structure, roles, and access hierarchy. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Published: 2026-09-11
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Concrete CMS version 9.2.0 to 9.5.2 features a missing authorization check in its REST API that allows an authenticated user with the groups:read scope to the full list of groups via the GET /ccm/api/1.0/groups endpoint. The flaw stems from the listGroups() method in concrete/src/Api/Controller/Groups.php, where a permissions checker callback unconditionally returns true, bypassing per‑object view checks. This results in the disclosure of the site’s entire group structure, roles and access hierarchy, representing a moderate severity information‑disclosure vulnerability. This missing authorization weakness is a CWE-862 flaw.

Affected Systems

Concrete CMS 9.2.0 through 9.5.2, with the vulnerability present in concrete/src/Api/Controller/Groups.php.

Risk and Exploitability

The CVSS score of 6.0 indicates a moderate severity vulnerability while the EPSS score of less than 1% reflects a low probability of exploitation. Concrete CMS is not listed in the CISA KEV catalog, and no public exploit is known. An attacker that possesses an authenticated API token with the groups:read scope can call the vulnerable endpoint, gather a comprehensive list of groups, and use that information for planning social engineering or privilege‑escalation attacks. The attack requires only an authenticated session; no special privileges are needed beyond the standard API permissions.

Generated by OpenCVE AI on September 21, 2026 at 04:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later where the groups:read scope is removed from API tokens that do not require group enumeration.
  • Block or restrict access to the /ccm/api/1.0/groups endpoint using a firewall or application‑level access control so that only privileged users can call it.
  • Audit existing API tokens to ensure they are assigned only to trusted, necessary tokens and remove any that are not required for application functionality.

Generated by OpenCVE AI on September 21, 2026 at 04:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditionally returns true, so no per-object (tree node) authorization is enforced when the group collection is returned. An authenticated user whose API token carries the groups:read scope can call GET /ccm/api/1.0/groups and receive every group on the site regardless of the view permissions on those groups, disclosing the organization's group structure, roles, and access hierarchy. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Title Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All Groups
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-11T19:22:43.122Z

Reserved: 2026-08-27T18:21:25.200Z

Link: CVE-2026-81908

cve-icon Vulnrichment

Updated: 2026-09-11T19:22:27.431Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T18:16:58.810

Modified: 2026-09-11T20:19:13.417

Link: CVE-2026-81908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:45:09Z

Weaknesses