Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API access
Published Sep 16, 2026
2.0
LOWCVSS 4.0
EPSS 0.26%
Description
Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authorization validator confirmed only that a token existed, had not expired, and had not been explicitly revoked, and deactivating a user did not revoke that user's outstanding tokens. As a result, a deactivated user retained full access to /ccm/api/1.0/* for the remaining lifetime of any token already issued to them. The same gap applied to accounts that had been deleted or locked pending a forced password reset. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.0 with vector CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Myq Larson for reporting.
Affected products
-
- Version 5.0.0StatusaffectedConstraints<=9.5.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Concrete CMS | Concrete CMS | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- https://documentation.concretecms.org/developers/introduction/version-history/954-release-notes release-notes
| Link | Providers | Tags |
|---|---|---|
| https://documentation.concretecms.org/developers/introduction/version-history/954-release-notes | release-notes |
Change history (0)
No recorded changes yet.