PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8347 Concrete CMS CVE debrief

A low-severity vulnerability was found in Concrete CMS 9.5.0 and below. The issue is an IDOR (Insecure Direct Object Reference) vulnerability combined with wrong authorization levels in the Express association Reorder dialog. This can lead to Cross-entity state tampering with view-only permission on one entry. To be affected, a website must be using Express and relying on Express entity ordering. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3. Although the CVSS score is low, it's essential to address this issue to prevent potential Cross-entity state tampering.

Vendor
Concrete CMS
Product
Unknown
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

Administrators and users of Concrete CMS 9.5.0 and below who utilize the Express association feature and rely on Express entity ordering should be aware of this vulnerability. Although the CVSS score is low, it's essential to address this issue to prevent potential Cross-entity state tampering. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.

Technical summary

The vulnerability is caused by an IDOR issue combined with incorrect authorization levels in the Express association Reorder dialog. This allows for Cross-entity state tampering with view-only permission on one entry. The CVSS v4.0 vector is AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. The affected version is Concrete CMS 9.5.0 and below, with a fix available in version 9.5.1. The issue requires a website to be using Express and relying on Express entity ordering.

Defensive priority

Low priority, but recommended to address to prevent potential Cross-entity state tampering.

Recommended defensive actions

  • Update to Concrete CMS version 9.5.1 or later
  • Review and adjust Express association Reorder dialog permissions
  • Monitor for suspicious activity related to Cross-entity state tampering
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-05-22T15:16:26.673Z and last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. The vulnerability was reported by Winston Crooker. Evidence of the vulnerability's existence is based on the CVE and NVD entries. However, additional verification is recommended to confirm the affected scope and severity. Defenders should verify the official advisory and CVE record for accurate information.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T15:16:26.673Z and has not been modified since then. The NVD entry is currently Analyzed.