CVE-2026-95653
Received Received - Intake

Concrete CMS Community Store Predictable Download Token Exposure

Vulnerability report for CVE-2026-95653, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: VulnCheck

Description

Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital goods purchased by other customers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
concretecms community_store to 2.7.8 (exc)
concrete_cms community_store to 2.7.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-340 The product uses a scheme that generates numbers or identifiers that are more predictable than required.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS Community Store before version 2.7.8 generates predictable digital download tokens using order creation timestamps instead of random values. This allows unauthenticated attackers to guess sequential order and file identifiers, calculate valid download tokens, and access digital products purchased by other customers.

Detection Guidance

To detect this vulnerability, check if your Concrete CMS Community Store version is below 2.7.8. Inspect download URLs for predictable tokens derived from order timestamps. Review server logs for unusual download requests or sequential order ID enumeration attempts.

Impact Analysis

Attackers could steal purchased digital goods by predicting download tokens. Customers may lose access to paid content, and businesses face financial and reputational damage. The vulnerability affects all versions before 2.7.8.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive digital products, potentially violating data protection requirements under GDPR or HIPAA if personal or confidential information is exposed. Non-compliance risks fines and legal consequences.

Mitigation Strategies

Immediately update Community Store to version 2.7.8 or later. Review and revoke any potentially exposed download tokens. Monitor for unauthorized access to digital products and audit order histories for anomalies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95653. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart