/Vulnerability Library

Concrete CMS <= 9.5.0 - Unauthenticated Conversation Message Disclosure (IDOR)

CVE-2026-8237
Verified

Description

Concrete CMS <= 9.5.0 contains an IDOR caused by insufficient access control in /ccm/frontend/conversations/message_detail endpoint, letting unauthenticated attackers enumerate conversation messages and attachments.

Severity

Medium

CVSS Score

5.3

Exploit Probability

1%

Affected Product

concrete_cms

Published Date

August 16, 2026

Template Author

pauullamm

CVE-2026-8237.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2026-8237
CWE ID:
cwe-862

References

https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-noteshttps://github.com/advisories/GHSA-xpgc-7vc2-8725https://nvd.nist.gov/vuln/detail/CVE-2026-8237

Remediation Steps

Update to a version later than 9.5.0 or the latest available version