Authorization Bypass in Concrete CMS Lightbox Calendar Feature
CVE-2026-18121
6.3MEDIUM
What is CVE-2026-18121?
The Concrete CMS calendar lightbox feature is susceptible to an authorization bypass vulnerability due to a lack of necessary verification at the endpoint responsible for viewing event occurrences. Untrusted users can exploit this flaw by supplying a sequential identifier to access and reveal event metadata from calendars without proper authorization. This could include sensitive details such as event titles, dates, descriptions, and configured attributes, potentially leading to unauthorized exposure of information within public calendar blocks.
Affected Version(s)
Concrete CMS 5.0.0 <= 9.5.2
