CVE-2026-68529
Received Received - Intake

Authorization Bypass in Concrete CMS via Advanced Search

Vulnerability report for CVE-2026-68529, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: ConcreteCMS

Description

Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action. The advanced_search() method in DashboardSelectableExpressEntryListTrait resolved an Express entity directly from a user-supplied entity ID and rendered that entity's entries without invoking canViewExpressEntries(), the per-entity permission check that the sibling results() action enforced. An authenticated dashboard user holding view_express_entries on a single Express entity could read the entries of any other entity, including secret attribute values, by requesting the advanced-search action with that entity's ID, disclosing form submissions and CRM-style records across the per-entity permission boundary that Express is designed to enforce.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concrete_cms concrete_cms From 9.0.0 (inc) to 9.5.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions 9.0.0 through 9.5.2 had a flaw in the Express entries advanced-search dashboard action. The system failed to properly check user permissions when resolving Express entities from user-supplied IDs. This allowed authenticated dashboard users with limited permissions to access and read entries from other Express entities, including sensitive data, by manipulating the entity ID in the advanced-search request.

Detection Guidance

This vulnerability requires authenticated access to the Concrete CMS dashboard. Check for unauthorized access to Express entries by reviewing logs for requests to the advanced-search action with unexpected entity IDs. No specific commands are provided in the context.

Impact Analysis

If you use Concrete CMS versions 9.0.0 through 9.5.2, an attacker with dashboard access could exploit this to read sensitive information from other users' Express entities. This includes form submissions or CRM records that should be restricted by per-entity permissions. The impact is limited to data exposure rather than system compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data stored in Express entities, potentially violating GDPR's data protection principles or HIPAA's requirements for safeguarding protected health information. Organizations using affected versions may face compliance risks due to potential data breaches.

Mitigation Strategies

Update Concrete CMS to a version beyond 9.5.2 to address the missing authorization check. Ensure only trusted users have dashboard access and review Express entity permissions to confirm proper access controls are enforced.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68529. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart