
CVE-2026-7887 For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminated employee) can sti… https://www.cve.org/CVERecord?id=CVE-2026-7887
Post summary
Concrete CMS versions 9.5.0 and below suffer an OAuth 2.0 Authorization‑Code Handler flaw that lets users flagged as inactive (uIsActive=0) bypass account status checks and authenticate.

