Contact Zero

CVE-2026-18110

concretecms concrete cms

score 30Public PoC ×1HIGH 8.7

Summary

Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates only a CSRF-style access token that is bound to the selector's display options rather than to the caller's identity or permissions, and that token is issued to anonymous visitors because the selector renders without an authorization check. Because an empty query resolves to a match-all filter, an unauthenticated attacker can submit an empty search and paginate the results to enumerate every backend account, disclosing the internal user ID, username, and email address of all administrative users, including the super-administrator (user ID 1). No password hashes or session material are disclosed The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 8.7 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks thirtythree and YesWeHack for reporting.

Published 2026-09-15 · first seen here 2026-10-10

Analysis & write-ups

No technical write-up from a research team yet. Contact Zero checks Unit 42, Google/Mandiant, Microsoft, Talos, CrowdStrike, Rapid7, watchTowr and others several times a day, plus NVD and CISA reference links.

Exploit availability

Public exploit code lowers the bar for attackers, so prioritise patching and hunting. These repositories are unverified. Fake PoCs that contain malware are common, so never run them outside an isolated lab.

Where it shows in your logs

Server or web application · Authentication bypass or missing authorisation medium confidence

What to look for

Data sources

Web server and WAF logs · ATT&CK DS0015 Application Log Content

Sentinel
W3CIISLogAppServiceHTTPLogsAzureDiagnostics (Application Gateway / Front Door WAF)_Im_WebSession
Splunk
Web.Webms:iis:autoaccess_combinedWAF / proxy sourcetypes
CrowdStrike
Falcon Next-Gen SIEM: third-party web / WAF / proxy logs

Process creation · ATT&CK DS0009 Process Creation

Sentinel
DeviceProcessEventsSecurityEvent (4688)Sysmon Event ID 1_Im_ProcessCreate
Splunk
Endpoint.ProcessesXmlWinEventLog:Microsoft-Windows-Sysmon/OperationalWinEventLog:Security (4688)
CrowdStrike
ProcessRollup2SyntheticProcessRollup2

File creation · ATT&CK DS0022 File Creation

Sentinel
DeviceFileEventsSysmon Event ID 11_Im_FileEvent
Splunk
Endpoint.FilesystemSysmon Event ID 11
CrowdStrike
NewExecutableWrittenNewScriptWritten*FileWritten events

Network connections · ATT&CK DS0029 Network Connection Creation / Network Traffic Flow

Sentinel
DeviceNetworkEventsCommonSecurityLog (firewall)_Im_NetworkSession
Splunk
Network_Traffic.All_TrafficFirewall sourcetypes (pan:traffic, fortigate_traffic, cisco:asa)
CrowdStrike
NetworkConnectIP4NetworkReceiveAcceptIP4NetworkConnectIP6

Authentication and sessions · ATT&CK DS0028 Logon Session Creation / DS0002 User Account Authentication

Sentinel
SigninLogsSecurityEvent (4624, 4625, 4648)DeviceLogonEventsIdentityLogonEvents_Im_Authentication
Splunk
Authentication.Authenticationpan:globalprotectVPN sourcetypes
CrowdStrike
UserLogonUserLogonFailed2Falcon Identity Protection events

Account and group changes · ATT&CK DS0002 User Account Creation / Modification

Sentinel
SecurityEvent (4720, 4728, 4732, 4756)AuditLogsIdentityDirectoryEvents
Splunk
Change.All_Changes (Account_Management)WinEventLog:Security (4720, 4732)
CrowdStrike
UserAccountCreatedUserAccountAddedToGroup

A generic baseline worked out from the product type and weakness (CWE-862), not a detection. Check table and field names against your environment. Hunt queries for Sigma, Splunk, Sentinel and CrowdStrike are coming.

References