CVE-2026-8337: Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys

Published May 21, 2026
·
Updated

Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unauthenticated attacker can vote in the restricted survey by submitting the restricted optionID through the public survey’s endpoint. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks  Zer0daySec https://github.com/Zee99y  for reporting

Affected Software

2 affected components
Concrete CMS Concrete CMS<=9.5.0
ConcreteCMS Concrete CMS<9.5.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Concrete CMS to a version that resolves this vulnerability.

    Fixed in 9.5.0

Event History

May 21, 2026
CVE Published
via MITRE·09:13 PM
Data Sourced
via MITRE·09:13 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 29, 58424
Event
via FIRST·08:59 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-8337?

The severity of CVE-2026-8337 is classified as medium with a CVSS score of 6.3.

2

How do I fix CVE-2026-8337?

To fix CVE-2026-8337, upgrade to Concrete CMS version 9.5.1 or higher, ensuring both public and private surveys are configured appropriately.

3

What is CVE-2026-8337?

CVE-2026-8337 is a vulnerability in Concrete CMS 9.5.0 and below that allows unauthenticated attackers to vote in restricted surveys due to improper access controls.

4

Who is affected by CVE-2026-8337?

Websites running Concrete CMS version 9.5.0 and below with both public and private surveys enabled are affected by CVE-2026-8337.

5

Can I exploit CVE-2026-8337 without authentication?

Yes, CVE-2026-8337 can be exploited by unauthenticated attackers who can manipulate survey options to submit votes in restricted surveys.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203