CVE-2026-18110 | Concrete CMS up to 9.5.2 Autocomplete Endpoint autocomplete improper authorization
A vulnerability was found in Concrete CMS up to 9.5.2. It has been declared as problematic. This affects an unknown function of the file /ccm/system/user/autocomplete of the component Autocomplete Endpoint. Executing a manipulation can lead to improper authorization.
This vulnerability appears as CVE-2026-18110. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More