PoC Published for CVE-2026-8337: CVE-2026-8337
July 31, 2026 · GitHub · Severity: CRITICAL
CVE-2026-8337 is an Insecure Direct Object Reference (IDOR) vulnerability discovered in Concrete CMS, specifically impacting its Survey feature. This flaw enables unauthenticated attackers to participate in restricted or private surveys under certain site configurations. Unlike CVE-2026-8347, which involved Express associations, this vulnerability directly exploits insecure access controls within the Survey functionality. A proof-of-concept (PoC) demonstrating the exploit has been published on GitHub by user aj2108, highlighting the technical details and potential misuse of the flaw. The vulnerability poses a significant risk to organizations using Concrete CMS, particularly those relying on private surveys for sensitive data collection or feedback. Unauthorized access to such surveys could lead to data breaches, manipulation of results, or exposure of confidential information. The publication of the PoC increases the urgency for affected entities to apply patches or mitigations promptly. Concrete CMS users are advised to review their site configurations and implement security updates to prevent exploitation of this vulnerability.
Key Takeaways
- This critical-severity vulnerability affects the affected product and could lead to system compromise.
- Organizations using affected products should review the published PoC and apply vendor patches immediately.
- Proof of Concept exploit published on GitHub: CVE-2026-8337. CVE-2026-8337 is an Insecure Direct Object Reference (IDOR) vulnerability in Concrete CMS. Proof-of-concept code lowers the barrier for exploitation — attackers and security tools alike can leverage it.