Authorization Bypass in Concrete CMS Calendar Event Editing
CVE-2026-68527

5.9MEDIUM

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-68527?

Concrete CMS versions 8.3.0 through 9.5.2 exhibit a vulnerability allowing an authorization bypass in the Calendar event editing interface. This vulnerability arises when the permission checks are performed against the calendar identifier received in the request. As a result, users with 'Add Event' access on a single calendar can not only read and modify events from calendars they are not authorized to access but also delete local occurrences of events. Furthermore, publishing a modified event to the live calendar can lead to the replacement of previously approved versions, necessitating appropriate workflow rights. This flaw emphasizes the importance of rigorous permission handling to ensure event security within the CMS.

Affected Version(s)

Concrete CMS 8.3.0 <= 9.5.2

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

winstoncrooker
.