CVE-2026-6826Concretecms · Concrete_cms
Vulnerability data via NVD (ingested)
Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller. Any unauthenticated visitor can request /ccm/system/dialogs/file/usage/{fID} with any file ID and receive a list of every page that references that file, including page IDs, handles, and full URLs. This includes pages that are otherwise restricted by permissions.The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.9 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Eldudareeno for reporting.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-6826product:"Concretecms Concrete Cms"http.html:"Concrete Cms"More intel sources (5)
vuln:CVE-2026-6826vulnerabilities.cve_id: CVE-2026-6826CVE-2026-6826CVE-2026-6826"CVE-2026-6826" exploit -site:nvd.nist.gov