CVE-2026-8239: Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/getrating' endpoint confirms existence and returns rating score for any message by ID. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Madani for reporting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8239?
The severity of CVE-2026-8239 is rated as medium with a CVSS score of 6.3.
How do I fix CVE-2026-8239?
To fix CVE-2026-8239, upgrade to Concrete CMS version 9.5.1 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-8239?
CVE-2026-8239 is an Insecure Direct Object Reference (IDOR) vulnerability.
Which versions of Concrete CMS are affected by CVE-2026-8239?
CVE-2026-8239 affects Concrete CMS 9.5.0 and below.
What does CVE-2026-8239 exploit?
CVE-2026-8239 exploits the '/ccm/frontend/conversations/get_rating' endpoint to confirm message existence and return ratings based on message ID.