CVE-2026-6826Disclosure(concretecms / concrete_cms)

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.  Any unauthenticated visitor can request /ccm/system/dialogs/file/usage/{fID} with any file ID and receive a list of every page that references that file, including page IDs, handles, and full URLs. This includes pages that are otherwise restricted by permissions.The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.9 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Eldudareeno for reporting.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • concrete_cms

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
concrete_cms

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-26: 1Mentions · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-13: 1Technical Details · 2026-05-26: 1Technical Details · 2026-08-13: 105-2608-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-6826 - medium 🚨 Concrete CMS <9.5.1 - Unauthenticated File Usage Disclosure > Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-6826 @pdnuclei #NucleiTemplates #cve

    Post summary

    A brief announcement of CVE-2026-6826 for Concrete CMS, noting an unauthenticated file usage disclosure and providing a link to a detection template.

    00013303
    1.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Concrete CMS, Unauthenticated File Usage Disclosure, #CVE-2026-6826 (Medium) https://dailycve.com/concrete-cms-unauthenticated-file-usage-disclosure-cve-2026-6826-medium/

    Post summary

    A Medium‑severity vulnerability (CVE-2026-6826) involving unauthenticated file usage in Concrete CMS has been disclosed, with details available at the provided link.

    0000039
    207 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appconcretecmsconcrete_cms---

Explore more