PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-7879 Concrete CMS CVE debrief

CVE-2026-7879 describes an authorization bypass in Concrete CMS 9.5.0 and below. The submit_password() method in concrete/controllers/single_page/download_file.php can allow file downloads without properly enforcing view_file permission checks. As described by the vendor/NVD record, this means non-passworded files can be downloaded even when access should be restricted, and password-protected files can be downloaded by anyone who knows the password regardless of file access permission. The issue was scored CVSS v4.0 6.3 (Medium) and reported by Youssef Eid.

Vendor
Concrete CMS
Product
Unknown
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-21
Original CVE updated
2026-07-23
Advisory published
2026-05-21
Advisory updated
2026-07-23

Who should care

Administrators and operators of Concrete CMS sites running 9.5.0 or earlier, especially deployments that rely on permission-restricted or password-protected file downloads. Security teams should also review any integrations or workflows that expose the affected download endpoint.

Technical summary

The flaw is an improper authorization issue (CWE-862) in the download_file controller’s submit_password() path. According to the supplied record, the affected logic bypasses the view_file permission check during download handling. That creates an access-control gap where restricted files may be retrieved without the expected authorization decision, including password-protected files when the password is known but the user lacks the underlying file permission.

Defensive priority

Medium

Recommended defensive actions

  • Review Concrete CMS installations for versions 9.5.0 and below and prioritize upgrading to the vendor-fixed release referenced in the 9.5.1 release notes.
  • Audit file-download access controls and confirm that view_file permissions are enforced before any download or password-handling step.
  • Restrict exposure of sensitive files until patches are applied, and re-check any content libraries that depend on password-only gating.
  • Validate logs for unexpected access to restricted download endpoints and investigate any anomalous retrievals of protected files.

Evidence notes

The vulnerability description in the supplied CVE record states that submit_password() in concrete/controllers/single_page/download_file.php bypasses the view_file permission check. NVD also associates the issue with CWE-862 (missing authorization). The only supplied vendor reference is the Concrete CMS 9.5.1 release notes URL, which supports that this is a Concrete CMS issue and provides the vendor-linked remediation context.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-7879 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-7879

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-7879 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7879

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.