CVE-2026-8337: Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unauthenticated attacker can vote in the restricted survey by submitting the restricted optionID through the public survey’s endpoint. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Zer0daySec https://github.com/Zee99y for reporting
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Concrete CMSto a version that resolves this vulnerability.Fixed in 9.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8337?
The severity of CVE-2026-8337 is classified as medium with a CVSS score of 6.3.
How do I fix CVE-2026-8337?
To fix CVE-2026-8337, upgrade to Concrete CMS version 9.5.1 or higher, ensuring both public and private surveys are configured appropriately.
What is CVE-2026-8337?
CVE-2026-8337 is a vulnerability in Concrete CMS 9.5.0 and below that allows unauthenticated attackers to vote in restricted surveys due to improper access controls.
Who is affected by CVE-2026-8337?
Websites running Concrete CMS version 9.5.0 and below with both public and private surveys enabled are affected by CVE-2026-8337.
Can I exploit CVE-2026-8337 without authentication?
Yes, CVE-2026-8337 can be exploited by unauthenticated attackers who can manipulate survey options to submit votes in restricted surveys.