Concrete CMS CVE-2026-85387: Deactivated Users Keep API Access via Live Tokens
In Concrete CMS before 9.5.4, the OAuth REST API validated only the bearer token, not the account state behind it. Deactivating, deleting or locking a user did not revoke issued tokens, leaving full access to /ccm/api/1.0/*. The flaw was rated CVSS 4.0 2.0; the fix ships in 9.5.4.
- Concrete CMS before 9.5.4 did not revoke tokens on deactivation, deletion or lockout
- A deactivated user retained full access to /ccm/api/1.0/* until the token expired
- The flaw was rated just 2.0 under CVSS 4.0 due to position and interaction requirements
- The same release fixed CVE-2026-81901 (8.7) and CVE-2026-85385, a stored XSS in the timezone field
Read next
Security