CVE-2026-81906
[UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that was fully authenticated for the callback response, with the login recorded and login events dispatched.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
| CWE | CWE-288 |
| Vendor | concrete cms |
| Product | concrete cms |
| Published | Sep 10, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for concrete cms concrete cms
Be the first to know when new unknown vulnerabilities affecting concrete cms concrete cms are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Concrete CMS / Concrete CMS
5.0.0 β€ 9.5.2
References
Credits
tenzai