CVE-2026-87031
Last modified
CVE-2026-87031 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check before creating an account. As a result, any valid OAuth token carrying the users:add scope, including a client_credentials token with no associated user context, could create active, validated user accounts, bypassing email verification and administrator approval. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check before creating an account. As a result, any valid OAuth token carrying the users:add scope, including a client_credentials token with no associated user context, could create active, validated user accounts, bypassing email verification and administrator approval. Under default registration settings the created accounts could then edit page content, providing a path to stored cross-site scripting and further compromise. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Concretecms | Concrete Cms | >= 9.2.0, < 9.5.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-87031?
How severe is CVE-2026-87031?
How do I fix CVE-2026-87031?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-87024Tanium addressed a SQL injection vulnerability in Asset.7.2
- CVE-2026-87025Tanium addressed an improper access controls vulnerability i…5.4
- CVE-2026-87026Tanium addressed an improper access controls vulnerability i…3.8
- CVE-2026-87028Concrete CMS 9 through 9.5.3 did not confirm that a board In…6.5
- CVE-2026-8703The Endless Scroll plugin for WordPress is vulnerable to Sto…6.4
- CVE-2026-87030Tanium addressed a path traversal vulnerability in Comply.8.5
- CVE-2026-87032Tanium addressed an information disclosure vulnerability in …4.3
- CVE-2026-87033Tanium addressed an improper access controls vulnerability i…5.4
- CVE-2026-87034Tanium addressed a SQL injection vulnerability in Comply.8.3
- CVE-2026-87035Tanium addressed an information disclosure vulnerability in …4.3
- CVE-2026-87036Tanium addressed an improper access controls vulnerability i…8.1
- CVE-2026-87037Tanium addressed an improper access controls vulnerability i…5.4
Are you affected by CVE-2026-87031?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
