Concrete CMS <9.5.1 - Unauthenticated File Usage Disclosure
CVE-2026-6826
Verified
Description
Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.
Severity
Medium
CVSS Score
6.9
Exploit Probability
1%
Published Date
August 8, 2026
Template Author
str4k3r
CVE-2026-6826.yaml
6.9Score
CVSS Metrics
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVE ID:
cve-2026-6826
CWE ID:
cwe-862
Remediation Steps
Update to the latest version beyond 9.5.0.