Unauthenticated Metadata Disclosure in Concrete CMS by Concrete5
CVE-2026-8240
6.3MEDIUM
What is CVE-2026-8240?
Concrete CMS versions up to 9.5.0 are susceptible to an issue where unauthenticated users can access page metadata across all pages configured with a summary template. This vulnerability can inadvertently expose sensitive information, such as the existence of private, draft, and restricted pages, along with crucial data like page titles, paths, descriptions, and authors. The Concrete CMS security team was made aware of this issue thanks to a report from Winston Crooker, highlighting the need for users to be vigilant regarding their installations.
Affected Version(s)
Concrete CMS 5.0 <= 9.5.0
