Unknown · Concrete Cms · CVE-2026-8237
**Name of the Vulnerable Software and Affected Versions**
Concrete CMS versions prior to 9.5.1
**Description**
An Insecure Direct Object Reference (IDOR) exists where the '/ccm/frontend/conversations/message detail' endpoint returns the full content of any conversation message. This allows an unauthenticated attacker to enumerate all conversation messages, including those from the moderation queue, member-only areas, and restricted pages. Additionally, file attachments containing download URLs are exposed.
**Recommendations**
Update to a version newer than 9.5.0.
As a temporary workaround, restrict access to the '/ccm/frontend/conversations/message detail' endpoint to minimize the risk of exploitation.