---
id: CVE-2026-68533
title: >-
  Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported
  files into the file manager before evaluating the "Add Message Attachments"
  permission, which was only checked after the file had been stored
summary: >-
  Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported
  files into the file manager before evaluating the "Add Message Attachments"
  permission, which was only checked after the file had been stored. A user
  denied that…
severity: low
cvss: 2.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-862
vendor: Concrete CMS
product: Concrete CMS
affected:
  - concrete_cms >= 5.0.0 <= 9.5.2
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:16:15.097'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-68533'
references:
  - url: >-
      https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes
    label: ff5b8ace-8b95-4078-9743-eac1ca5451de
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T19:26:40.530850Z'
cvssSource: cna
ingestedAt: '2026-09-15T18:41:59.179Z'
epss: 0.00286
epssPercentile: 0.21445
---

## Overview

Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluating the "Add Message Attachments" permission, which was only checked after the file had been stored. A user denied that permission, or an unauthenticated visitor on a guest-posting configuration, could import approved files of allowed types into the file manager. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
