PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81906 Concrete CMS CVE debrief

A vulnerability in Concrete CMS OAuth callback login path prior to version 9.5.3 allows a deactivated or unvalidated user with an existing OAuth binding to complete authentication and receive a fully authenticated session. The login is recorded and login events are dispatched. This issue has a CVSS v4.0 score of 6.3. Affected product deployments should be identified and verified for exposure. Defenders should assess the impact and prioritize updates to Concrete CMS to ensure version 9.5.3 or later is used.

Vendor
Concrete CMS
Product
Unknown
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Defenders responsible for Concrete CMS installations, especially those using versions prior to 9.5.3, should assess exposure and verify user authentication and session management. This includes reviewing and updating Concrete CMS to version 9.5.3 or later, monitoring login events and user authentication, and implementing compensating controls for exposed systems.

Why it matters

CVE-2026-81906 allows deactivated or unvalidated users to authenticate and receive a fully authenticated session in Concrete CMS installations prior to version 9.5.3. Defenders should verify user authentication and session management, prioritize updates, and monitor login events.

  • Verification of user authentication and session management is required to prevent unauthorized access.
  • Defenders should assess exposure and prioritize updates to Concrete CMS to ensure version 9.5.3 or later is used.
  • Monitoring login events and user authentication can help detect potential exploitation attempts.

Technical summary

The vulnerability in Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that was fully authenticated for the callback response. This issue allows unauthorized access to Concrete CMS installations prior to version 9.5.3, with defenders needing to verify user authentication and session management to prevent exploitation.

Defensive priority

Defenders should prioritize verifying user authentication and session management in Concrete CMS installations, especially for versions prior to 9.5.3.

Recommended defensive actions

  • Verify user authentication and session management in Concrete CMS installations, especially for versions prior to 9.5.3.
  • Check for and apply updates to Concrete CMS to ensure version 9.5.3 or later is used.
  • Monitor login events and user authentication in Concrete CMS installations.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its CVSS v4.0 score and vector. A reference to Concrete CMS release notes is also provided. The vulnerability allows deactivated or unvalidated users to authenticate and receive a fully authenticated session in Concrete CMS installations prior to version 9.5.3. The CVE record was published on 2026-09-11T00:19:48.977Z and has not been modified since then. No additional information on exploitation or affected scope is available.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81906 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81906

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81906 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81906

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.