Feed/CVE-2026-8347
CVE-2026-8347LOWCVSS 0.0

Concrete CMS is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog

Published May 26, 2026·Updated Jun 29, 2026

NVD Description

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. Thanks Winston Crooker for reporting.

Affected Packages (1)

concrete5/concrete5COMPOSER
Fixed in 9.5.1

Public Exploits & PoCs1 found

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free