CVE-2026-8240: Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure in Backend\SummaryTemplate
Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured summary template, revealing the existence of private, draft, and restricted pages while leaking title, path, description, and author information. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8240?
The severity of CVE-2026-8240 is classified as medium with a CVSS score of 6.3.
How do I fix CVE-2026-8240?
To fix CVE-2026-8240, update Concrete CMS to version 9.5.1 or later.
What information can be disclosed due to CVE-2026-8240?
CVE-2026-8240 allows unauthenticated users to access page metadata, revealing details about private, draft, and restricted pages.
Which versions of Concrete CMS are affected by CVE-2026-8240?
Concrete CMS versions 9.5.0 and below are vulnerable to CVE-2026-8240.
What type of vulnerability is CVE-2026-8240?
CVE-2026-8240 is a vulnerability related to unauthenticated page metadata disclosure.