CVE-2026-7881
Concrete CMS is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block
EPSS 0.20%
Description
Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express form submissions. The Concrete CMS security team thanks Tristan Madani for reporting this issue.
How to fix CVE-2026-7881
To remediate CVE-2026-7881, upgrade the affected package to a fixed version below.
- Packagist/concrete5/concrete5—upgrade to 9.5.1 or later
Is CVE-2026-7881 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 9.5.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |