Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint
Published May 21, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.74%
Description
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, including messages from restricted pages, member-only areas, and the moderation queue. File attachments with download URLs are also exposed. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Eldudareeno for reporting.
Affected products
-
Affected
- ≥ 5.0, ≤ 9.5.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Concrete CMS | Concrete CMS | unaffected | Affected
|
- < 9.5.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes release-notesRelease Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31352 Advisory
- https://github.com/advisories/GHSA-xpgc-7vc2-8725 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-8237
| Link | Providers | Tags |
|---|---|---|
| https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes | release-notesRelease Notes | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31352 | Advisory | |
| https://github.com/advisories/GHSA-xpgc-7vc2-8725 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-8237 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub