Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access… (CVE-2026-81921)
Concrete CMS versions 8.5.3 through 9.5.2 use an unmodified OAuth 2.0 refresh-token grant implementation that does not verify if an account is active when issuing new access tokens. This allows a user with a valid refresh token obtained while active to continue generating access tokens even after their account is deactivated or suspended, effectively bypassing account deactivation for API access. The vulnerability has a low CVSS v4.0 score of 2.3.
AI Analysis
Technical Summary
Concrete CMS versions 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant. This implementation issues new access tokens from a valid refresh token without verifying the associated account's active status. Consequently, a user who obtained a refresh token while active can continue to mint valid access tokens after being deactivated or suspended (uIsActive=0). This means that deactivating an account does not revoke its API access, potentially allowing continued access despite suspension.
Potential Impact
The vulnerability allows continued API access for users whose accounts have been deactivated or suspended, as the refresh token grant does not check the user's active status before issuing new access tokens. This could lead to unauthorized API access by users who should no longer have it. However, the overall severity is low, reflecting limited impact and exploitability.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, organizations should consider additional controls around refresh token issuance and account deactivation processes to mitigate risk.
Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access… (CVE-2026-81921)
Description
Concrete CMS versions 8.5.3 through 9.5.2 use an unmodified OAuth 2.0 refresh-token grant implementation that does not verify if an account is active when issuing new access tokens. This allows a user with a valid refresh token obtained while active to continue generating access tokens even after their account is deactivated or suspended, effectively bypassing account deactivation for API access. The vulnerability has a low CVSS v4.0 score of 2.3.
CVSS v4.0
Affected software
pkg:github/concretecms/concrete5Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Concrete CMS versions 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant. This implementation issues new access tokens from a valid refresh token without verifying the associated account's active status. Consequently, a user who obtained a refresh token while active can continue to mint valid access tokens after being deactivated or suspended (uIsActive=0). This means that deactivating an account does not revoke its API access, potentially allowing continued access despite suspension.
Potential Impact
The vulnerability allows continued API access for users whose accounts have been deactivated or suspended, as the refresh token grant does not check the user's active status before issuing new access tokens. This could lead to unauthorized API access by users who should no longer have it. However, the overall severity is low, reflecting limited impact and exploitability.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, organizations should consider additional controls around refresh token issuance and account deactivation processes to mitigate risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-46mx-9v73-g459
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-81921"]
- Database Specific Severity
- LOW
- Cvss Version
- 4.0
Threat ID: 6aaa07ea55bf5e2cf5ea3d39
Added to database: 09/16/2026, 03:07:22 UTC
Last enriched: 09/16/2026, 04:58:54 UTC
Last updated: 09/17/2026, 01:49:01 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.