PatchSiren cyber security CVE debrief
CVE-2026-8347 Concrete CMS CVE debrief
A low-severity vulnerability was found in Concrete CMS 9.5.0 and below. The issue is an IDOR (Insecure Direct Object Reference) vulnerability combined with wrong authorization levels in the Express association Reorder dialog. This can lead to Cross-entity state tampering with view-only permission on one entry. To be affected, a website must be using Express and relying on Express entity ordering. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3. Although the CVSS score is low, it's essential to address this issue to prevent potential Cross-entity state tampering.
- Vendor
- Concrete CMS
- Product
- Unknown
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-22
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-22
- Advisory updated
- 2026-07-23
Who should care
Administrators and users of Concrete CMS 9.5.0 and below who utilize the Express association feature and rely on Express entity ordering should be aware of this vulnerability. Although the CVSS score is low, it's essential to address this issue to prevent potential Cross-entity state tampering. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.
Technical summary
The vulnerability is caused by an IDOR issue combined with incorrect authorization levels in the Express association Reorder dialog. This allows for Cross-entity state tampering with view-only permission on one entry. The CVSS v4.0 vector is AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. The affected version is Concrete CMS 9.5.0 and below, with a fix available in version 9.5.1. The issue requires a website to be using Express and relying on Express entity ordering.
Defensive priority
Low priority, but recommended to address to prevent potential Cross-entity state tampering.
Recommended defensive actions
- Update to Concrete CMS version 9.5.1 or later
- Review and adjust Express association Reorder dialog permissions
- Monitor for suspicious activity related to Cross-entity state tampering
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-05-22T15:16:26.673Z and last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. The vulnerability was reported by Winston Crooker. Evidence of the vulnerability's existence is based on the CVE and NVD entries. However, additional verification is recommended to confirm the affected scope and severity. Defenders should verify the official advisory and CVE record for accurate information.
Official resources
-
CVE-2026-8347 CVE record
CVE.org
-
CVE-2026-8347 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
ff5b8ace-8b95-4078-9743-eac1ca5451de - Release Notes, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T15:16:26.673Z and has not been modified since then. The NVD entry is currently Analyzed.