Junglewise Threat Intelligence

CVE-2026-8347: Concrete CMS IDOR in Express association Reorder dialog

CVE-2026-8347 · Severity: medium · CVSS 4.3 · Published 2026-05-22

Technologies: Concrete CMS, concrete5/concrete5 (Packagist). Vendors: Concrete CMS, Packagist.

Executive brief

Concrete CMS is a content management system used to build and manage websites. A security flaw in the 'Express' data management component allows a user with limited 'view-only' permissions to change the display order of data entries. This could allow an unauthorized user to manipulate how information is presented to others, potentially disrupting business workflows or data organization.

Technical details

Concrete CMS versions 9.5.0 and below contain an Insecure Direct Object Reference (IDOR) and improper authorization level check within the Express association Reorder dialog. An authenticated attacker with low-level 'view-only' permissions can exploit this flaw to reorder Express entities, a task that should require higher administrative privileges. This results in cross-entity state tampering. The vulnerability specifically affects sites utilizing the Express component and relying on entity ordering. The issue is addressed in version 9.5.1.

Affected products

  • Concrete CMS Concrete CMS 5.0 to 9.5.0

Timeline

  • 2026-05-22: advisory: NVD and Vendor advisory published
  • 2026-05-22: patched: Fixed in version 9.5.1 release notes

References

Related threats