PatchSiren

Concrete CMS CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Concrete CMS CVE published 2026-05-21

CVE-2026-6826

CVE-2026-6826 is an unauthenticated information-disclosure issue in Concrete CMS 9.5.0 and earlier. A missing permission check in the file usage controller can let a remote visitor query file-usage details for a file ID and receive references to pages that use that file, including page IDs, handles, and full URLs. Because the response can include pages that are otherwise restricted, the issue can expose s [truncated]