CVE-2026-8337
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unauthenticated attacker can vote in the restricted survey by submitting the restricted optionID through the public survey’s endpoint. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Zer0daySec https://github.com/Zee99y for reporting
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.19%
- CWE
- CWE-639, CWE-565
- Published
- 2026-05-21
- Last modified
- 2026-05-22
Affected products
- Concrete CMS Concrete CMS
Weakness type
Related vulnerabilities
- CVE-2026-18121 — Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}).
- CVE-2026-80434 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-81210 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-9225 — Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation
- CVE-2026-68527 — Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog
- CVE-2026-88877 — Traefik v3.7.0 Authentication Bypass via from-to-www-redirect
- CVE-2026-88865 — AVideo Missing Authorization via getRestream.json.php
- CVE-2026-80354 — Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace