CVE-2026-7886 | Concrete CMS up to 9.5.0 AddMessage/UpdateMessage attachments authorization
A vulnerability identified as critical has been detected in Concrete CMS CMS up to 9.5.0. Affected by this vulnerability is the function AddMessage/UpdateMessage. This manipulation of the argument attachments causes authorization bypass.
This vulnerability is handled as CVE-2026-7886. The attack can be initiated remotely. There is not any exploit available.