CVE-2026-8347
MEDIUMConcrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog
Title source: cnaExploitation Summary
EIP tracks 2 public exploits for CVE-2026-8347. PoCs published by aj2108.
AI-analyzed exploit summary Detailed technical analysis of CVE-2026-8337, an IDOR vulnerability in Concrete CMS's Survey feature, where unauthenticated attackers can manipulate survey results by submitting crafted optionIDs to public endpoints, bypassing authorization checks for restricted surveys.
Description
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog. This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Exploits (2)
Detailed technical analysis of CVE-2026-8337, an IDOR vulnerability in Concrete CMS's Survey feature, where unauthenticated attackers can manipulate survey results by submitting crafted optionIDs to public endpoints, bypassing authorization checks for restricted surveys.
The repository contains a README describing CVE-2026-8347, an IDOR and authorization flaw in Concrete CMS's Express association Reorder dialog, but lacks exploit code or technical depth for execution. The vulnerability allows unauthorized reordering of associations with only view permissions.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N