SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81908

MEDIUM · CVSS 6 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Concrete CMS versions 9.2.0 to 9.5.2 are vulnerable due to a missing authorization check in the REST API Groups list endpoint, allowing authenticated users with the appropriate API token to access all groups on the site without proper permission validation. This could lead to the unauthorized disclosure of sensitive information regarding the organization's group structure and access hierarchy. Organizations using these versions of Concrete CMS should prioritize patching this vulnerability to protect against potential data exposure.

CVE
CVE-2026-81908
Severity
MEDIUM
CVSS
6
EPSS
0.21%

Original NVD Description

Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditionally returns true, so no per-object (tree node) authorization is enforced when the group collection is returned. An authenticated user whose API token carries the groups:read scope can call GET /ccm/api/1.0/groups and receive every group on the site regardless of the view permissions on those groups, disclosing the organization's group structure, roles, and access hierarchy. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.0 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.