CVE-2026-8327
Last modified
CVE-2026-8327 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw POST array to UserInfo::update() without field whitelisting resulting in password change without requiring the current password and also resulting in registered users able to disable the per-user-IP-pinning in the session validator which is meant to detect hijacking. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks 0x4c616e for reporting.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw POST array to UserInfo::update() without field whitelisting resulting in password change without requiring the current password and also resulting in registered users able to disable the per-user-IP-pinning in the session validator which is meant to detect hijacking. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks 0x4c616e for reporting.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Concretecms | Concrete Cms | < 9.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-8327?
How severe is CVE-2026-8327?
How do I fix CVE-2026-8327?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-83264Vulnerability in the Oracle Product Lifecycle Analytics prod…8.4
- CVE-2026-83265Vulnerability in the Oracle Web Services Manager product of …8.2
- CVE-2026-83266Vulnerability in the Oracle JDeveloper product of Oracle Fus…8.2
- CVE-2026-83267Vulnerability in the Oracle BI Publisher product of Oracle A…8.5
- CVE-2026-83268Vulnerability in the Oracle BI Publisher product of Oracle A…9.1
- CVE-2026-83269Vulnerability in the Oracle BI Publisher product of Oracle A…9.8
- CVE-2026-83270Vulnerability in the Oracle Business Intelligence Enterprise…7.5
- CVE-2026-83271Vulnerability in the RDBMS component of Oracle Database Serv…8.8
- CVE-2026-83272Vulnerability in the Oracle Text component of Oracle Databas…8.5
- CVE-2026-83273Vulnerability in the Oracle Business Intelligence Enterprise…7.2
- CVE-2026-83274Vulnerability in the Oracle Agile PLM MCAD Connector product…5.5
- CVE-2026-83276Vulnerability in the Helidon product of Oracle Fusion Middle…7.5
Are you affected by CVE-2026-8327?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
