Concrete CMS Missing Authorization Vulnerability in Bulk User Assignment Dashboard Allowing Privilege Escalation

Vulnerability

A vulnerability exists in Concrete CMS versions through 9.5.0, where missing authorization in the bulk user assignment dashboard can lead to privilege escalation by allowing any authenticated user to manipulate group assignments. This includes adding users to any group or removing legitimate administrators. The issue arises from inadequate authorization checks in the 'bulk_user_assignment.php' file, enabling unauthorized changes to user group memberships.

Impact

Exploitation of this vulnerability could result in unauthorized users being granted administrative privileges or legitimate admins being removed from their roles.

Remediation

Users can upgrade to Concrete CMS version 9.5.1 or later, where this vulnerability has been fixed.

Added: May 21, 2026, 9:24 PM
Updated: May 21, 2026, 9:24 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
5.4
remediation
7.7
relevance
9.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.