CVE-2026-81908 | Concrete CMS up to 9.5.2 REST API Groups list endpoint Groups.php listGroups improper authorization
A vulnerability was found in Concrete CMS up to 9.5.2 and classified as problematic. This affects the function listGroups of the file concrete/src/Api/Controller/Groups.php of the component REST API Groups list endpoint. Such manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-81908. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More