Executive brief
Concrete CMS, a platform used for building and managing websites, contains a security flaw in its calendar component. This vulnerability allows an unauthorized person to view private calendar information that should not be accessible to them. By using a publicly visible calendar as a starting point, an attacker can gain access to data from other private calendars on the same system.
Technical details
Concrete CMS versions 9.5.0 and below are vulnerable to an authorization bypass (CWE-639) within the Calendar Event Frontend Dialog. The flaw allows a remote, unauthenticated attacker to use a public calendar block as a pivot point to disclose data from private calendars. This occurs because the system fails to properly validate authorization when accessing event details through the frontend dialog interface. An attacker can exploit this by manipulating user-controlled keys to access cross-calendar data. The issue is resolved in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS <= 9.5.0
Timeline
- 2026-05-21: disclosed
- 2026-05-21: advisory
- 2026-05-21: patched: Fixed in version 9.5.1