PoC Published for CVE-2026-47668: CVE-2026-47668
July 31, 2026 · GitHub · Severity: CRITICAL
A proof-of-concept (PoC) has been published for CVE-2026-8347, an Insecure Direct Object Reference (IDOR) and authorization flaw in Concrete CMS versions 9.5.0 and earlier. The vulnerability, located in the Express association Reorder dialog, allows users with only view permissions to improperly modify the ordering of associations for other entities. This could enable unauthorized data manipulation by low-privileged users. The flaw specifically affects organizations using vulnerable versions of Concrete CMS, an open-source content management system. While no active exploitation has been reported yet, the public PoC (hosted on GitHub) increases the risk of attacks. Administrators are urged to update to a patched version or apply mitigations to prevent potential data integrity breaches. The issue highlights the importance of proper access control validation in web applications.
Key Takeaways
- A public proof-of-concept exploit has been published for CVE-2026-47668, demonstrating how the vulnerability can be exploited. Proof of Concept exploit published on GitHub: CVE-2026-47668. Unauthenticated RCE in DBGate <= 7.1.8.
- Organizations using affected products should review the published PoC and apply vendor patches immediately.
- Proof-of-concept code lowers the barrier for exploitation — attackers and security tools alike can leverage it.