chiprook
← Security
SecurityOctober 3, 2026, 05:21

Concrete CMS CVE-2026-85387: Deactivated Users Keep API Access via Live Tokens

In Concrete CMS before 9.5.4, the OAuth REST API validated only the bearer token, not the account state behind it. Deactivating, deleting or locking a user did not revoke issued tokens, leaving full access to /ccm/api/1.0/*. The flaw was rated CVSS 4.0 2.0; the fix ships in 9.5.4.

Concrete CMS CVE-2026-85387: Deactivated Users Keep API Access via Live Tokens
#ConcreteCMS
Read next
Security

osm plugin keeps API keys away from Claude Code

Security

Ghost CMS discloses six CVEs, including CVSS 8.1 staff session bypass

Security

ShinyHunters hacked Clop leak site via Grav CMS path traversal flaw

Policy

Indonesia presses Meta to speed up deactivation of under-16 accounts