Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller. Any unauthenticated visitor can request /ccm/system/dialogs/file/usage/{fID} with any file ID and receive a list of every page that references that file, including page IDs, handles, and full URLs. This includes pages that are otherwise restricted by permissions.The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.9 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Eldudareeno for reporting.
References
| Link | Resource |
|---|---|
| https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes | Release Notes |
Configurations
History
26 May 2026, 14:59
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| References | () https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes - Release Notes | |
| First Time |
Concretecms concrete Cms
Concretecms |
|
| CPE | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* |
21 May 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-21 21:16
Updated : 2026-05-26 14:59
NVD link : CVE-2026-6826
Mitre link : CVE-2026-6826
CVE.ORG link : CVE-2026-6826
JSON object : View
Products Affected
concretecms
- concrete_cms
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
