Junglewise Threat Intelligence

CVE-2026-87028: Concrete CMS access control bypass in board custom-slot preview

CVE-2026-87028 · Severity: medium · CVSS 6.5 · Published 2026-09-16

Executive brief

Concrete CMS is a website building and content management platform. A flaw in the board custom-slot preview feature allows an authenticated user with board editing permissions to view restricted page content (titles, descriptions) from other board instances they should not have access to. This could expose sensitive page information to unauthorized employees or collaborators.

Technical details

The custom-slot preview endpoint in Concrete CMS 9.0–9.5.3 fails to validate that a submitted board InstanceItem belongs to the board instance the requesting user is authorized to edit. Additionally, the endpoint does not enforce page-view permissions before returning page-backed summary content. An authenticated user with edit-board-contents permission on one board can submit the identifier of an item from a different board instance to retrieve sensitive summary fields (page title, description) from pages they would otherwise be forbidden to access. The attack requires prior authentication and knowledge of target item identifiers but no user interaction.

Affected products

  • Concrete CMS Concrete CMS 9.0 through 9.5.3

Timeline

  • 2026-09-16: disclosed: CVE-2026-87028 published

References

Related threats