Junglewise Threat Intelligence

CVE-2026-8204: Concrete CMS authorization bypass in Calendar Event Frontend Dialog

CVE-2026-8204 · Severity: medium · CVSS 5.3 · Published 2026-05-21

Technologies: Concrete CMS, concrete5/concrete5 (Packagist). Vendors: Concrete CMS, Packagist.

Executive brief

Concrete CMS, a platform used for building and managing websites, contains a security flaw in its calendar component. This vulnerability allows an unauthorized person to view private calendar information that should not be accessible to them. By using a publicly visible calendar as a starting point, an attacker can gain access to data from other private calendars on the same system.

Technical details

Concrete CMS versions 9.5.0 and below are vulnerable to an authorization bypass (CWE-639) within the Calendar Event Frontend Dialog. The flaw allows a remote, unauthenticated attacker to use a public calendar block as a pivot point to disclose data from private calendars. This occurs because the system fails to properly validate authorization when accessing event details through the frontend dialog interface. An attacker can exploit this by manipulating user-controlled keys to access cross-calendar data. The issue is resolved in version 9.5.1.

Affected products

  • Concrete CMS Concrete CMS <= 9.5.0

Timeline

  • 2026-05-21: disclosed
  • 2026-05-21: advisory
  • 2026-05-21: patched: Fixed in version 9.5.1

References

Related threats