CVE-2026-8239
MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-8239. PoCs published by aj2108.
AI-analyzed exploit summary Detailed technical analysis of CVE-2026-8239, an IDOR vulnerability in Concrete CMS 9.5.0 and earlier, where the /ccm/frontend/conversations/get_rating endpoint fails to perform authorization checks, allowing attackers to enumerate message IDs and retrieve rating scores without proper permissions.
Description
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms existence and returns rating score for any message by ID. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Madani for reporting.
Exploits (1)
Detailed technical analysis of CVE-2026-8239, an IDOR vulnerability in Concrete CMS 9.5.0 and earlier, where the /ccm/frontend/conversations/get_rating endpoint fails to perform authorization checks, allowing attackers to enumerate message IDs and retrieve rating scores without proper permissions.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N