Medium severity4.3NVD Advisory· Published May 22, 2026· Updated Jul 23, 2026
CVE-2026-8347
CVE-2026-8347
Description
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog. This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
concrete5/concrete5Packagist | < 9.5.1 | 9.5.1 |
Affected products
2- Range: <=9.5.0
Patches
Vulnerability mechanics
References
3- documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notesnvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-jqvq-gv67-3567ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-8347ghsaADVISORY
News mentions
1- Concrete CMS: 25 CVEs Disclosed Together, 12 High-Severity CSRF Bugs Lead the BatchVypr Intelligence · May 22, 2026