CVE-2026-8236

Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns internal site structure data (page IDs, versions, URL paths) to anyone who sends a GET request. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Configurations

Configuration 1 (hide)

cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*

History

23 Jul 2026, 16:10

Type Values Removed Values Added
Summary
  • (es) Concrete CMS 9.5.0 y versiones anteriores es vulnerable a IDOR combinado con una puerta de autenticación ausente. El endpoint /ccm/system/dialogs/file/usage/{fID} acepta un ID de archivo entero en la URL y devuelve datos de la estructura interna del sitio (IDs de página, versiones, rutas de URL) a cualquiera que envíe una solicitud GET. El equipo de seguridad de Concrete CMS otorgó a esta vulnerabilidad una puntuación CVSS v.4.0 de 6.3 con el vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Gracias a Winston Crooker por informar.

26 May 2026, 17:37

Type Values Removed Values Added
First Time Concretecms concrete Cms
Concretecms
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
References () https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes - () https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes - Release Notes
CPE cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*

21 May 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 22:16

Updated : 2026-07-23 16:10


NVD link : CVE-2026-8236

Mitre link : CVE-2026-8236

CVE.ORG link : CVE-2026-8236


JSON object : View

Products Affected

concretecms

  • concrete_cms
CWE
CWE-862

Missing Authorization