
🚨 CVE-2026-8237 - medium 🚨 Concrete CMS <= 9.5.0 - Unauthenticated Conversation Message Disclosure (IDOR) > Concrete CMS <= 9.5.0 contains an IDOR caused by insufficient access control in /ccm/... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-8237 @pdnuclei #NucleiT...
Post summary
The tweet announces a medium‑severity IDOR in Concrete CMS (<=9.5.0) that permits unauthenticated message disclosure, linking to a ProjectDiscovery library entry but not providing a patch or exploit.
