Concrete CMS <= 9.5.0 - Unauthenticated Conversation Message Disclosure (IDOR)
CVE-2026-8237
Verified
Description
Concrete CMS <= 9.5.0 contains an IDOR caused by insufficient access control in /ccm/frontend/conversations/message_detail endpoint, letting unauthenticated attackers enumerate conversation messages and attachments.
Severity
Medium
CVSS Score
5.3
Exploit Probability
1%
Affected Product
concrete_cms
Published Date
August 16, 2026
Template Author
pauullamm
CVE-2026-8237.yaml
5.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2026-8237
CWE ID:
cwe-862
Remediation Steps
Update to a version later than 9.5.0 or the latest available version