---
id: CVE-2026-87031
title: >-
  n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST
  /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php)
  did not perform a permission check before creating an account
summary: >-
  n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST
  /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php)
  did not perform a permission check before creating an account. As a result,
  any …
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
vendor: concretecms
product: concrete_cms
affected:
  - 'concrete_cms >= 9.2.0, < 9.5.3'
patched:
  - concrete_cms 9.5.3
published: '2026-09-16'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:51:32.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87031'
references:
  - url: >-
      https://documentation.concretecms.org/developers/introduction/version-history/954-release-notes
    label: ff5b8ace-8b95-4078-9743-eac1ca5451de
tags:
  - nvd
  - cve.org
epss: 0.00336
epssPercentile: 0.24404
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T17:33:23.721726Z'
scores:
  nvd: 2.7
  cna: 2.1
ingestedAt: '2026-09-16T16:59:56.550Z'
---

## Overview

n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check before creating an account. As a result, any valid OAuth token carrying the users:add scope, including a client_credentials token with no associated user context, could create active, validated user accounts, bypassing email verification and administrator approval. Under default registration settings the created accounts could then edit page content, providing a path to stored cross-site scripting and further compromise. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.1 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

## Affected

- `concrete_cms >= 9.2.0, < 9.5.3`

## Remediation

Upgrade past the affected range:

- `concrete_cms 9.5.3`
