Authorization Bypass Vulnerability in Concrete CMS by Concrete5
CVE-2026-8204
6.3MEDIUM
What is CVE-2026-8204?
Concrete CMS versions up to 9.5.0 are susceptible to an authorization bypass that enables unauthorized users to access private calendar information. This issue arises in the Calendar Event Frontend Dialog, where a public calendar block may serve as an entry point for exploiting private data across calendars. This vulnerability highlights the importance of rigorous access controls to protect sensitive calendar data from unauthorized disclosure.
Affected Version(s)
Concrete CMS 5 <= 9.5.0
