Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creation (CVE-2026-87031) | HOL Guard CVE