CVE-2026-87031: Concretecms Concrete CMS

Low severity, CVSS 2.7. EPSS: 0.3% chance of exploitation in the next 30 days.

n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check before creating an account. As a result, any valid OAuth token carrying the users:add scope, including a client_credentials token with no associated user context, could create active, validated user accounts, bypassing email verification and administrator approval. Under default registration settings the created accounts could then edit page content, providing a path to stored cross-site scripting and further compromise. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

Affected products

  • Concretecms Concrete CMS: from 9.2.0, before 9.5.3 (fixed in 9.5.3)

Published 2026-09-16. Last modified 2026-09-21.