In Concrete CMS 9.2.0 to 9.5.2, Missing Authorization in REST API Users update() and change_password Enables Account Takeover. (CVE-2026-18115) | HOL Guard CVE