CVE-2026-18110-PoC
Author
flenz00
Published
2026-09-28
Stars
0
Forks
0
Repository
Description
Proof-of-Concept for CVE-2026-18110
CVE-CVE-2026-18110 Details
Severity
HIGH
CVSS Score
7.5
CWE
CWE-862
Description
Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates only a CSRF-style access token that is bound to the selector's display options rather than to the caller's identity or permissions, and that token is issued to anonymous visitors because the selector renders without an authorization check. Because ...
Related PoCs for CVE-2026-18110
No other PoCs found for this CVE.