Unauthenticated Metadata Disclosure in Concrete CMS by Concrete5
CVE-2026-8240

6.3MEDIUM

Key Information:

Vendor
CVE Published:
21 May 2026

What is CVE-2026-8240?

Concrete CMS versions up to 9.5.0 are susceptible to an issue where unauthenticated users can access page metadata across all pages configured with a summary template. This vulnerability can inadvertently expose sensitive information, such as the existence of private, draft, and restricted pages, along with crucial data like page titles, paths, descriptions, and authors. The Concrete CMS security team was made aware of this issue thanks to a report from Winston Crooker, highlighting the need for users to be vigilant regarding their installations.

Affected Version(s)

Concrete CMS 5.0 <= 9.5.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Winston Crooker
.