Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wmw3-3fv3-h54w | Concrete CMS has a session-hardening bypass and allows password change without reauthorization |
Tue, 26 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 22 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Concretecms
Concretecms concrete Cms |
|
| Vendors & Products |
Concretecms
Concretecms concrete Cms |
Thu, 21 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw POST array to UserInfo::update() without field whitelisting resulting in password change without requiring the current password and also resulting in registered users able to disable the per-user-IP-pinning in the session validator which is meant to detect hijacking. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks 0x4c616e for reporting. | |
| Title | Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. | |
| Weaknesses | CWE-269 CWE-620 CWE-915 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ConcreteCMS
Published:
Updated: 2026-05-22T13:15:58.343Z
Reserved: 2026-05-11T14:21:53.569Z
Link: CVE-2026-8327
Updated: 2026-05-22T13:15:54.967Z
Status : Analyzed
Published: 2026-05-21T22:16:50.373
Modified: 2026-06-17T11:03:48.800
Link: CVE-2026-8327
No data.
OpenCVE Enrichment
Updated: 2026-05-21T23:00:14Z
Github GHSA