A Deactivated User With a Live Token: Reading Concrete CMS CVE-2026-85387 as a Revocation Gap
A Deactivated User With a Live Token: Reading Concrete CMS CVE-2026-85387 as a Revocation Gap Revocation is the part of identity that nobody tests Identity work concentrates on issuing credentials and verifying them. Revoking them is treated as an administrative outcome rather than a security control. CVE-2026-85387 in Concrete CMS is a useful case because the defect sits entirely inside that neglected half of the lifecycle. Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone. The resource server's authorization validator confirmed that a token existed,
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in