PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8347 Concrete CMS CVE debrief

A low-severity vulnerability was found in Concrete CMS 9.5.0 and below. The issue is an IDOR (Insecure Direct Object Reference) vulnerability combined with wrong authorization levels in the Express association Reorder dialog. This can lead to Cross-entity state tampering with view-only permission on one entry. To be affected, a website must be using Express and relying on Express entity ordering. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3. Although the CVSS score is low, it's essential to address this issue to prevent potential Cross-entity state tampering.

Vendor
Concrete CMS
Product
Unknown
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

Administrators and users of Concrete CMS 9.5.0 and below who utilize the Express association feature and rely on Express entity ordering should be aware of this vulnerability. Although the CVSS score is low, it's essential to address this issue to prevent potential Cross-entity state tampering. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.

Technical summary

The vulnerability is caused by an IDOR issue combined with incorrect authorization levels in the Express association Reorder dialog. This allows for Cross-entity state tampering with view-only permission on one entry. The CVSS v4.0 vector is AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. The affected version is Concrete CMS 9.5.0 and below, with a fix available in version 9.5.1. The issue requires a website to be using Express and relying on Express entity ordering.

Defensive priority

Low priority, but recommended to address to prevent potential Cross-entity state tampering.

Recommended defensive actions

  • Update to Concrete CMS version 9.5.1 or later
  • Review and adjust Express association Reorder dialog permissions
  • Monitor for suspicious activity related to Cross-entity state tampering
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-05-22T15:16:26.673Z and last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. The vulnerability was reported by Winston Crooker. Evidence of the vulnerability's existence is based on the CVE and NVD entries. However, additional verification is recommended to confirm the affected scope and severity. Defenders should verify the official advisory and CVE record for accurate information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8347 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8347

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8347 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8347

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de - Release Notes, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.