CVE-CVE-2026-18110
Severity
HIGH
CVSS Score
7.5
Description
Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates only a CSRF-style access token that is bound to the selector's display options rather than to the caller's identity or permissions, and that token is issued to anonymous visitors because the selector renders without an authorization check. Because ...
PoCs for CVE-CVE-2026-18110
CVE-2026-18110-PoC
General
0
flenz00
2026-09-28