← Back to Feed

PoC Published for CVE-2026-8347: CVE-2026-8347

CVE-2026-8347

July 31, 2026 · GitHub · Severity: CRITICAL

A proof-of-concept (PoC) has been published for CVE-2026-8347, a vulnerability affecting Concrete CMS versions 9.5.0 and earlier. The flaw is an Insecure Direct Object Reference (IDOR) combined with incorrect authorization levels, specifically within the Express association Reorder dialog. This allows users with only view permissions to manipulate the ordering of associations for another entity, potentially leading to unauthorized changes in the system. The PoC repository, hosted on GitHub by user aj2108, was created on July 31, 2026, and provides a detailed demonstration of the exploit. Organizations using Concrete CMS versions 9.5.0 or earlier are at risk, as the vulnerability could be exploited by attackers to alter data structures without proper authorization. This poses a significant security threat, particularly for websites relying on Concrete CMS for content management. The publication of the PoC increases the urgency for affected entities to apply patches or updates to mitigate the risk. Concrete CMS users should monitor for official updates from the vendor and implement necessary security measures to prevent potential exploitation of this vulnerability.

CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, allowing a user with only view permissions on an Express entry to modify the ordering of associations for another entity. Repository: https://github.com/aj2108/CVE-2026-8347 Stars: 0 Created: 2026-07-31T08:34:50Z

Key Takeaways

  • Organizations using affected products should review the published PoC and apply vendor patches immediately.
  • Proof of Concept exploit published on GitHub: CVE-2026-8347. CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authori. Proof-of-concept code lowers the barrier for exploitation — attackers and security tools alike can leverage it.
☕ Buy a Coffee