Junglewise Threat Intelligence

CVE-2026-81905: Concrete CMS validation hash type confusion

CVE-2026-81905 · Severity: info · CVSS 6.3 · Published 2026-09-11

Technologies: Concrete CMS. Vendors: Concrete CMS.

Executive brief

Concrete CMS stores validation hashes used for multiple purposes (email verification, password reset, persistent login) in a single database table without enforcing type during redemption. An attacker who obtains any valid hash through interception or disclosure can submit it to the wrong endpoint to perform a different action—for example, using a long-lived registration hash to reset a user's password. This amplifies the impact of email interception, log exposure, or similar hash disclosure incidents.

Technical details

Concrete CMS stores validation hashes in a single table with a type column, but the redemption code resolves hashes by value alone without verifying the type field. A 60-day registration hash can be redeemed at the password-change endpoint, and a password-reset hash can be redeemed at the email-validation endpoint. Attack requires prior hash disclosure (email interception, log exposure, SSRF against internal mail relay, etc.); the vulnerability does not create a standalone entry point but amplifies the impact of hash leakage. No authentication or user interaction is required once a hash is obtained. Patches are available in Concrete CMS 9.5.3 and later.

Affected products

  • Concrete CMS Concrete CMS below 9.5.3

Timeline

  • 2026-09-11: disclosed

References

Related threats