PT-2026-42546 · Unknown · Concrete Cms

Vincent55

·

Published

2026-05-21

·

Updated

2026-05-26

·

CVE-2026-8350

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Concrete CMS versions 9.5.0 and earlier
Description Missing authorization in the 'bulk user assignment.php' endpoint allows an authenticated user with access to the bulk user assignment dashboard page to perform privilege escalation to the Administrative Group. This allows the user to add any email address to any group or remove legitimate administrators.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-8350

Affected Products

Concrete Cms