Authorization Bypass in Concrete CMS Lightbox Calendar Feature
CVE-2026-18121

6.3MEDIUM

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-18121?

The Concrete CMS calendar lightbox feature is susceptible to an authorization bypass vulnerability due to a lack of necessary verification at the endpoint responsible for viewing event occurrences. Untrusted users can exploit this flaw by supplying a sequential identifier to access and reveal event metadata from calendars without proper authorization. This could include sensitive details such as event titles, dates, descriptions, and configured attributes, potentially leading to unauthorized exposure of information within public calendar blocks.

Affected Version(s)

Concrete CMS 5.0.0 <= 9.5.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

riodrwn
.