CVE-2026-8347: Concrete CMS is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog
(updated )
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog. This can cause Cross-entity state tampering with view-only permission on one entry. To be affected, a website has to be using express and relying on express entity ordering. Thanks Winston Crooker for reporting.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-8347 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →