← Back to Feed

PoC Published for CVE-2026-47668: CVE-2026-47668

CVE-2026-47668

July 31, 2026 · GitHub · Severity: CRITICAL

A proof-of-concept (PoC) has been published for CVE-2026-8347, an Insecure Direct Object Reference (IDOR) and authorization flaw in Concrete CMS versions 9.5.0 and earlier. The vulnerability, located in the Express association Reorder dialog, allows users with only view permissions to improperly modify the ordering of associations for other entities. This could enable unauthorized data manipulation by low-privileged users. The flaw specifically affects organizations using vulnerable versions of Concrete CMS, an open-source content management system. While no active exploitation has been reported yet, the public PoC (hosted on GitHub) increases the risk of attacks. Administrators are urged to update to a patched version or apply mitigations to prevent potential data integrity breaches. The issue highlights the importance of proper access control validation in web applications.

CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, allowing a user with only view permissions on an Express entry to modify the ordering of associations for another entity. Repository: https://github.com/aj2108/CVE-2026-8347 Stars: 0 Created: 2026-07-31T08:34:50Z

Key Takeaways

  • A public proof-of-concept exploit has been published for CVE-2026-47668, demonstrating how the vulnerability can be exploited. Proof of Concept exploit published on GitHub: CVE-2026-47668. Unauthenticated RCE in DBGate <= 7.1.8.
  • Organizations using affected products should review the published PoC and apply vendor patches immediately.
  • Proof-of-concept code lowers the barrier for exploitation — attackers and security tools alike can leverage it.
☕ Buy a Coffee