CVE-2026-7879: Concrete CMS has an unauthorized file access issue
(updated )
In Concrete CMS 9.5.0 and below, the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access since downloading permission-restricted files bypasses the view_file permission check. Files without passwords can be downloaded and any user who knows a file’s password can download a password protected file regardless of whether they have permission to access the file. The Concrete CMS security team thanks Youssef Eid for reporting this issue.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-7879 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →