Back

LOW

Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API access

Published Sep 16, 2026

Description

Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authorization validator confirmed only that a token existed, had not expired, and had not been explicitly revoked, and deactivating a user did not revoke that user's outstanding tokens. As a result, a deactivated user retained full access to /ccm/api/1.0/* for the remaining lifetime of any token already issued to them. The same gap applied to accounts that had been deleted or locked pending a forced password reset. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Myq Larson for reporting.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ConcreteCMS
Published Sep 16, 2026
Updated Sep 17, 2026
Reserved Sep 3, 2026
CISA Vulnrichment
Updated Sep 17, 2026
NVD
Status Undergoing Analysis
Modified Sep 17, 2026
Red Hat
Severity n/a
Public date n/a