Description
n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check before creating an account. As a result, any valid OAuth token carrying the users:add scope, including a client_credentials token with no associated user context, could create active, validated user accounts, bypassing email verification and administrator approval. Under default registration settings the created accounts could then edit page content, providing a path to stored cross-site scripting and further compromise. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Published: 2026-09-16
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated creation of user accounts enabling content editing and cross‑site scripting
Action: ApplyPatch
AI Analysis

Impact

Concrete CMS versions 9.2.0 through 9.5.3 contain a deficiency in the REST API user creation endpoint (POST /ccm/api/1.0/users). The controller does not perform a permission check before creating an account. Any OAuth token that carries the users:add scope, including a client_credentials token with no user context, can be used to create active, verified accounts. Those accounts bypass email verification and administrator approval, and under the CMS’s default registration settings can edit page content, providing a path to stored cross‑site scripting and further compromise.

Affected Systems

Concrete CMS installations running versions 9.2.0 up to and including 9.5.3 are affected. Administrators should confirm the exact version deployed and plan an update accordingly.

Risk and Exploitability

The CVSS score of 2.1 denotes a low overall severity, and the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker must first obtain an OAuth token with the users:add scope, which may be obtained through compromised credentials or a misconfigured OAuth client. Once the token is in hand, the attack can be carried out remotely via the public REST API. Although the immediate impact is limited to the creation of new user accounts, those accounts can subsequently edit content, leading to potential stored XSS and data tampering. The scope of impact therefore extends beyond user creation to content integrity and site trust.

Generated by OpenCVE AI on September 18, 2026 at 02:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Concrete CMS to the latest release that includes the authorization check for the user creation endpoint. Refer to the project release notes for the specific version that fixed the issue.
  • If an immediate update is not feasible, restrict the OAuth scopes so that no token has users:add, or limit the token type to authorized human users only.
  • Reconfigure the CMS to disable the REST API user creation endpoint, or remove it from the API routing table.
  • As a temporary measure, enforce email verification and administrator approval for new user registrations in the CMS configuration settings.

Generated by OpenCVE AI on September 18, 2026 at 02:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check before creating an account. As a result, any valid OAuth token carrying the users:add scope, including a client_credentials token with no associated user context, could create active, validated user accounts, bypassing email verification and administrator approval. Under default registration settings the created accounts could then edit page content, providing a path to stored cross-site scripting and further compromise. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Title Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creation
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-17T17:33:33.219Z

Reserved: 2026-09-08T18:13:52.425Z

Link: CVE-2026-87031

cve-icon Vulnrichment

Updated: 2026-09-17T17:33:28.621Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T17:18:16.703

Modified: 2026-09-21T17:51:32.133

Link: CVE-2026-87031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses