Description
Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authorization validator confirmed only that a token existed, had not expired, and had not been explicitly revoked, and deactivating a user did not revoke that user's outstanding tokens. As a result, a deactivated user retained full access to /ccm/api/1.0/* for the remaining lifetime of any token already issued to them. The same gap applied to accounts that had been deleted or locked pending a forced password reset. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Myq Larson for reporting.
Published: 2026-09-16
Score: 2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized API Access
Action: Apply Update
AI Analysis

Impact

Concrete CMS versions prior to 9.5.4 allow a deactivated or locked user to continue using previously issued OAuth bearer tokens to access the REST API under the /ccm/api/1.0/* endpoint. The authorization validator only checks that a token exists, is not expired, and has not been explicitly revoked; it does not verify that the associated user account remains active. As a result, an account that has been deactivated, deleted, or locked pending reset retains full API access for the remaining token lifetime. The vulnerability is an example of access control weakness (CWE‑613) and can lead to unauthorized information disclosure or operation execution via the API. It does not provide direct remote code execution, but it permits continued use of a privileged interface that would otherwise be revoked.

Affected Systems

Concrete CMS versions before 9.5.4. The affected component is the OAuth authentication module used by the /ccm/api/1.0/* REST API. Only those versions lacking the 9.5.4 update are impacted.

Risk and Exploitability

The CVSS score is 2.0, indicating low severity, and the EPSS score is below 1%, suggesting very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via HTTP requests to the REST API using a bearer token that was issued before an account was deactivated. An attacker who already holds such a token could continue to use it; a new token would not be issued to a deactivated account. No additional system compromise is directly possible, but the breach allows continued API use with the existing permissions of the user.

Generated by OpenCVE AI on September 18, 2026 at 01:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.4 or later to enforce re‑authentication of OAuth tokens against account status
  • Revoke or rotate all outstanding OAuth tokens for deactivated or locked users so no lingering tokens remain valid
  • Verify that the system correctly denies access when an account is deactivated or locked, and audit token usage to confirm enforcement

Generated by OpenCVE AI on September 18, 2026 at 01:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Fri, 18 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authorization validator confirmed only that a token existed, had not expired, and had not been explicitly revoked, and deactivating a user did not revoke that user's outstanding tokens. As a result, a deactivated user retained full access to /ccm/api/1.0/* for the remaining lifetime of any token already issued to them. The same gap applied to accounts that had been deleted or locked pending a forced password reset. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Myq Larson for reporting.
Title Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API access
Weaknesses CWE-613
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-17T17:32:47.476Z

Reserved: 2026-09-03T18:09:33.097Z

Link: CVE-2026-85387

cve-icon Vulnrichment

Updated: 2026-09-17T17:32:43.414Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T18:17:17.850

Modified: 2026-09-21T17:51:12.423

Link: CVE-2026-85387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration