Concrete CMS <9.5.1 - Unauthenticated File Usage Disclosure
Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller. References: https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes https://www.concretecms.org/security https://nvd.nist.gov/vuln/detail/CVE-2026-6826 https://vulnerability.circl.lu/vuln/cve-2026-6826 Remediation: Update to the latest version beyond 9.5.0.
Used 2.7k times · 1 assets checked · url