CVE-2026-8347

MEDIUM

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-8347. PoCs published by aj2108.

AI-analyzed exploit summary Detailed technical analysis of CVE-2026-8337, an IDOR vulnerability in Concrete CMS's Survey feature, where unauthenticated attackers can manipulate survey results by submitting crafted optionIDs to public endpoints, bypassing authorization checks for restricted surveys.

Description

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

Exploits (2)

github WRITEUP
by aj2108 · poc
https://github.com/aj2108/CVE-2026-8337

Detailed technical analysis of CVE-2026-8337, an IDOR vulnerability in Concrete CMS's Survey feature, where unauthenticated attackers can manipulate survey results by submitting crafted optionIDs to public endpoints, bypassing authorization checks for restricted surveys.

Classification
Writeup 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Concrete CMS 9.5.0 and earlier
No auth needed
Prerequisites: Target site must have both a public and a restricted survey configured · Attacker must intercept or craft HTTP requests to identify valid optionIDs
mistral-large-3 · analyzed Aug 01, 2026 Full analysis →
github STUB
by aj2108 · poc
https://github.com/aj2108/CVE-2026-8347

The repository contains a README describing CVE-2026-8347, an IDOR and authorization flaw in Concrete CMS's Express association Reorder dialog, but lacks exploit code or technical depth for execution. The vulnerability allows unauthorized reordering of associations with only view permissions.

Classification
Stub 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: Concrete CMS versions up to and including 9.5.0
Auth required
Prerequisites: Valid user account with view permissions on an Express entry · Access to the Express association Reorder dialog
mistral-large-3 · analyzed Jul 31, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 4.3
EPSS 0.0018
EPSS Percentile 7.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (3)
Concrete CMS/Concrete CMS 5.0 - 9.5.0
concrete5/concrete5 0 - 9.5.1Packagist
concretecms/concrete_cms < 9.5.1
Published May 22, 2026
Tracked Since May 22, 2026