CVE-2026-7887LOWCVSS 0.0

Concrete CMS: OAuth 2.0 Authorization-Code Handler Bypasses Account Status

Published May 22, 2026·Updated Jun 24, 2026

Description

For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminated employee) can still authenticate via OAuth and receive valid API tokens. 

Affected Packages (1)

concrete5/concrete5COMPOSER
Fixed in 9.5.1

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free