CVE-2026-7879 | Concrete CMS up to 9.5.0 download_file.php submit_password authorization
A vulnerability classified as problematic was found in Concrete CMS up to 9.5.0. This affects the function submit_password of the file concrete/controllers/single_page/download_file.php. Executing a manipulation can lead to missing authorization.
This vulnerability is tracked as CVE-2026-7879. The attack can be launched remotely. No exploit exists.