PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8239 Concrete CMS CVE debrief

CVE-2026-8239 is a medium-severity insecure direct object reference in Concrete CMS 9.5.0 and below. The affected endpoint can reveal whether a message exists and return its rating score when accessed by message ID, indicating missing authorization checks on a network-reachable path.

Vendor
Concrete CMS
Product
Unknown
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-21
Original CVE updated
2026-07-23
Advisory published
2026-05-21
Advisory updated
2026-07-23

Who should care

Concrete CMS site owners, administrators, and developers running version 9.5.0 or earlier, especially teams exposing or integrating the frontend conversations feature.

Technical summary

The NVD record classifies this issue as CWE-862 (Missing Authorization) with CVSS v4.0 6.3. According to the supplied description, the '/ccm/frontend/conversations/get_rating' endpoint confirms the existence of a message and returns its rating score for a given message ID, without the access control expected for a protected object lookup.

Defensive priority

Medium. This is remotely reachable and requires no privileges or user interaction, so it should be prioritized for remediation on any exposed Concrete CMS deployment, especially where message metadata should remain private.

Recommended defensive actions

  • Review the official Concrete CMS release notes linked in the NVD record and update to a vendor-remediated version once identified.
  • Audit access control on '/ccm/frontend/conversations/get_rating' and any related message-ID lookup paths to ensure object-level authorization is enforced.
  • Restrict exposure of frontend conversation endpoints where practical, especially to unauthenticated users or unnecessary network paths.
  • Monitor logs for repeated or unusual requests to message-ID-based endpoints that may indicate enumeration of conversation objects.
  • If custom extensions or integrations depend on this endpoint, verify they do not assume message visibility without explicit authorization checks.

Evidence notes

The source corpus includes an NVD record for CVE-2026-8239 stating that Concrete CMS 9.5.0 and below are vulnerable to IDOR at '/ccm/frontend/conversations/get_rating'. The record provides CVSS v4.0 6.3 (AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N) and CWE-862. The only cited vendor reference in the supplied data is Concrete CMS 9.5.1 release notes; no additional remediation details were provided in the corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8239 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8239

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8239 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8239

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.