CVE-2026-7881

MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to IDOR in the Express Entry Detail block

Title source: cna
STIX 2.1

Description

Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express form submissions. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Madani for reporting.

References (1)

Core 1

Scores

CVSS v3 4.3
EPSS 0.0020
EPSS Percentile 10.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
Concrete CMS/Concrete CMS 5.0 - 9.5.0
concretecms/concrete_cms < 9.5.1
Published May 21, 2026
Tracked Since May 22, 2026