Authorization Bypass in Concrete CMS Calendar Event Editing
CVE-2026-68527
What is CVE-2026-68527?
Concrete CMS versions 8.3.0 through 9.5.2 exhibit a vulnerability allowing an authorization bypass in the Calendar event editing interface. This vulnerability arises when the permission checks are performed against the calendar identifier received in the request. As a result, users with 'Add Event' access on a single calendar can not only read and modify events from calendars they are not authorized to access but also delete local occurrences of events. Furthermore, publishing a modified event to the live calendar can lead to the replacement of previously approved versions, necessitating appropriate workflow rights. This flaw emphasizes the importance of rigorous permission handling to ensure event security within the CMS.
Affected Version(s)
Concrete CMS 8.3.0 <= 9.5.2
