PatchSiren cyber security CVE debrief
CVE-2026-87031 Concrete CMS CVE debrief
A vulnerability in Concrete CMS 9.2.0 through 9.5.3 allows for the creation of active, validated user accounts without proper permission checks, potentially leading to stored cross-site scripting. This issue arises from the REST API user creation endpoint's failure to perform necessary permission checks before creating an account. As a result, any valid OAuth token carrying the users:add scope can be exploited to create accounts, bypassing email verification and administrator approval. The impact is significant as created accounts could then edit page content, providing a path to stored cross-site scripting and further compromise. Concrete CMS administrators and users with access
- Vendor
- Concrete CMS
- Product
- Unknown
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-21
Who should care
Concrete CMS administrators and users with access to the REST API user creation endpoint should assess exposure and verify user account creation settings. This includes reviewing OAuth token configurations and monitoring for suspicious user account creation activity. The impact of this vulnerability is significant for those with administrative privileges and access to user account creation functionalities.
Why it matters
The vulnerability allows for the creation of active, validated user accounts without proper permission checks, potentially leading to stored cross-site scripting. Concrete CMS administrators and users with access to the REST API user creation endpoint should assess exposure and verify user account creation settings. The impact is limited by the requirement for a valid OAuth token carrying the users:add scope. Defenders should prioritize verifying user account creation settings and OAuth token configurations, and monitor for suspicious user account creation activity.
- Potential for unauthorized user account creation.
- Possible exploitation of stored cross-site scripting vulnerabilities.
- Need for verification of user account creation settings and OAuth token configurations.
- Importance of monitoring for suspicious user account creation activity.
Technical summary
The REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 did not perform a permission check before creating an account, allowing for the creation of active, validated user accounts with a valid OAuth token carrying the users:add scope. This oversight enables potential attackers to bypass email verification and administrator approval, leading to possible exploitation of stored cross-site scripting vulnerabilities. The issue highlights the need for verifying user account creation settings and OAuth token configurations to mitigate potential risks.
Defensive priority
Assess exposure and verify user account creation settings.
Recommended defensive actions
- Assess exposure by verifying user account creation settings and OAuth token configurations.
- Verify email verification and administrator approval settings for user accounts.
- Monitor for suspicious user account creation activity.
- Apply vendor-provided patches or updates to address the vulnerability.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability was reported by Winston Crooker and assigned a CVSS v4.0 score of 2.1. The affected versions are Concrete CMS 9.2.0 through 9.5.3. This issue is grounded in the official CVE record and NIST NVD detail page. Defenders should verify user account creation settings, OAuth token configurations, and monitor for suspicious user account creation activity. The creation of active, validated user accounts without proper permission checks is a critical issue that needs to be addressed promptly.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87031 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87031
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87031 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87031
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://documentation.concretecms.org/developers/introduction/version-history/954-release-notes
ff5b8ace-8b95-4078-9743-eac1ca5451de - Broken Link
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.