Executive brief
Concrete CMS, a content management system used for building websites, contains a security flaw in its Calendar component. This vulnerability allows unauthorized individuals to bypass access controls and view private or restricted event details that should not be publicly accessible. This could lead to the exposure of sensitive scheduling information or internal company events.
Technical details
Concrete CMS versions 9.5.0 and below are vulnerable to a Direct Request (Forced Browsing) vulnerability (CWE-425) within the Calendar Block component. The root cause is that the 'action_get_events' function fails to perform a 'canView' permission check on the calendar object before returning data. A remote, unauthenticated attacker can exploit this by sending a network request to the affected endpoint to retrieve event details that are otherwise restricted. This results in a loss of confidentiality for calendar data. The issue is addressed in version 9.5.1.
Affected products
- Concrete CMS Concrete CMS <= 9.5.0
Timeline
- 2026-05-21: advisory: GitHub Advisory published
- 2026-05-21: disclosed: NVD published date
- 2026-05-21: patched: Version 9.5.1 released with fix