Authorization Bypass Vulnerability in Concrete CMS by Concrete5
CVE-2026-8204

6.3MEDIUM

Key Information:

Vendor
CVE Published:
21 May 2026

What is CVE-2026-8204?

Concrete CMS versions up to 9.5.0 are susceptible to an authorization bypass that enables unauthorized users to access private calendar information. This issue arises in the Calendar Event Frontend Dialog, where a public calendar block may serve as an entry point for exploiting private data across calendars. This vulnerability highlights the importance of rigorous access controls to protect sensitive calendar data from unauthorized disclosure.

Affected Version(s)

Concrete CMS 5 <= 9.5.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Winston Crooker
.