CVE-2026-7887: Concrete CMS: OAuth 2.0 Authorization-Code Handler Bypasses Account Status
(updated )
For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminated employee) can still authenticate via OAuth and receive valid API tokens.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-7887 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →