Junglewise Threat Intelligence

CVE-2026-8239: Concrete CMS IDOR in conversation rating endpoint

CVE-2026-8239 · Severity: medium · CVSS 4 · Published 2026-05-21

Technologies: Concrete CMS, concrete5/concrete5 (Packagist). Vendors: Concrete CMS, Packagist.

Executive brief

Concrete CMS, a popular content management system, contains a security flaw that allows unauthorized users to view information about private messages. By manipulating message identifiers, an attacker can confirm if a specific message exists and view its rating score. This could lead to the exposure of metadata about private communications within the platform.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Concrete CMS versions 9.5.0 and below due to missing authorization checks in the '/ccm/frontend/conversations/get_rating' endpoint. An unauthenticated attacker can send network requests to this endpoint with arbitrary message IDs to confirm the existence of messages and retrieve their associated rating scores. This occurs because the application fails to verify if the requester has the appropriate permissions to access the metadata of the specified message object. The issue is addressed in version 9.5.1.

Affected products

  • Concrete CMS Concrete CMS <= 9.5.0

Timeline

  • 2026-05-21: disclosed: NVD publication date
  • 2026-05-22: advisory: GitHub Advisory published
  • 2026-06-24: patched: Advisory updated with patch information

References

Related threats