{"dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": {"cveId": "CVE-2026-8337", "assignerOrgId": "ff5b8ace-8b95-4078-9743-eac1ca5451de", "state": "PUBLISHED", "assignerShortName": "ConcreteCMS", "dateReserved": "2026-05-11T15:59:55.797Z", "datePublished": "2026-05-21T21:13:07.640Z", "dateUpdated": "2026-05-22T13:13:57.212Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "ff5b8ace-8b95-4078-9743-eac1ca5451de", "shortName": "ConcreteCMS", "dateUpdated": "2026-05-21T21:13:07.640Z"}, "title": "Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys", "problemTypes": [{"descriptions": [{"lang": "en", "cweId": "CWE-639", "description": "CWE-639 Authorization bypass through User-Controlled key", "type": "CWE"}]}, {"descriptions": [{"lang": "en", "cweId": "CWE-565", "description": "CWE-565 Reliance on cookies without validation and integrity checking", "type": "CWE"}]}], "impacts": [{"capecId": "CAPEC-31", "descriptions": [{"lang": "en", "value": "CAPEC-31 Accessing/Intercepting/Modifying HTTP Cookies"}]}, {"capecId": "CAPEC-1", "descriptions": [{"lang": "en", "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"}]}], "affected": [{"vendor": "Concrete CMS", "product": "Concrete CMS", "collectionURL": "https://github.com/concretecms/concretecms", "repo": "https://github.com/concretecms/concretecms", "versions": [{"status": "affected", "version": "5.0", "lessThanOrEqual": "9.5.0", "versionType": "git"}], "defaultStatus": "unaffected"}], "descriptions": [{"lang": "en", "value": "Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys.\u00a0To be vulnerable, a\u00a0site would have to be configured in such a way that both public and private surveys are present on the site. An\u00a0unauthenticated attacker can vote in the restricted survey by submitting the restricted optionID through the public survey\u2019s endpoint.\u00a0The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of\u00a06.3 with vector\u00a0CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks\u00a0 Zer0daySec https://github.com/Zee99y \u00a0for reporting", "supportingMedia": [{"type": "text/html", "base64": false, "value": "<div>Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys.&nbsp;<span>To be vulnerable, a</span><span>&nbsp;site would have to be configured in such a way that both public and private surveys are present on the site. An&nbsp;</span><span>unauthenticated attacker can vote in the restricted survey by submitting the restricted </span><code>optionID</code><span> through the public survey\u2019s endpoint.&nbsp;</span><span>The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of</span><span>&nbsp;6.3 with vector&nbsp;</span><span>CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks&nbsp;</span><span><a href=\"https://github.com/Zee99y\">Zer0daySec</a>&nbsp;for reporting</span></div>"}]}], "references": [{"url": "https://documentation.concretecms.org/9-x/developers/introduction/version-history/951-release-notes", "tags": ["release-notes"]}], "metrics": [{"format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}], "cvssV4_0": {"attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "PRESENT", "privilegesRequired": "NONE", "userInteraction": "NONE", "vulnConfidentialityImpact": "NONE", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "LOW", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "MEDIUM", "baseScore": 6.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}}], "credits": [{"lang": "en", "value": "Zer0daySec (GitHub: https://github.com/Zee99y)", "type": "finder"}], "source": {"defect": ["HackerOne"], "advisory": "https://hackerone.com/reports/3647015", "discovery": "EXTERNAL"}, "x_generator": {"engine": "Vulnogram 1.0.2"}}, "adp": [{"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2026-05-22T13:13:50.327710Z", "id": "CVE-2026-8337", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-05-22T13:13:57.212Z"}}]}}