Impact
Concrete CMS versions prior to 9.5.4 allow a deactivated or locked user to continue using previously issued OAuth bearer tokens to access the REST API under the /ccm/api/1.0/* endpoint. The authorization validator only checks that a token exists, is not expired, and has not been explicitly revoked; it does not verify that the associated user account remains active. As a result, an account that has been deactivated, deleted, or locked pending reset retains full API access for the remaining token lifetime. The vulnerability is an example of access control weakness (CWE‑613) and can lead to unauthorized information disclosure or operation execution via the API. It does not provide direct remote code execution, but it permits continued use of a privileged interface that would otherwise be revoked.
Affected Systems
Concrete CMS versions before 9.5.4. The affected component is the OAuth authentication module used by the /ccm/api/1.0/* REST API. Only those versions lacking the 9.5.4 update are impacted.
Risk and Exploitability
The CVSS score is 2.0, indicating low severity, and the EPSS score is below 1%, suggesting very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via HTTP requests to the REST API using a bearer token that was issued before an account was deactivated. An attacker who already holds such a token could continue to use it; a new token would not be issued to a deactivated account. No additional system compromise is directly possible, but the breach allows continued API use with the existing permissions of the user.
OpenCVE Enrichment