CVE-2026-18122 | Concrete CMS up to 9.5.2 Express REST API includes improper authorization

SecurityVulns

A vulnerability was found in Concrete CMS up to 9.5.2. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component Express REST API. The manipulation of the argument includes leads to improper authorization.

This vulnerability is traded as CVE-2026-18122. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More