Junglewise Threat Intelligence

CVE-2026-8205: Concrete CMS authorization bypass in Calendar Block

CVE-2026-8205 · Severity: medium · CVSS 5.3 · Published 2026-05-21

Technologies: Concrete CMS, concrete5/concrete5 (Packagist). Vendors: Concrete CMS, Packagist.

Executive brief

Concrete CMS, a content management system used for building websites, contains a security flaw in its Calendar component. This vulnerability allows unauthorized individuals to bypass access controls and view private or restricted event details that should not be publicly accessible. This could lead to the exposure of sensitive scheduling information or internal company events.

Technical details

Concrete CMS versions 9.5.0 and below are vulnerable to a Direct Request (Forced Browsing) vulnerability (CWE-425) within the Calendar Block component. The root cause is that the 'action_get_events' function fails to perform a 'canView' permission check on the calendar object before returning data. A remote, unauthenticated attacker can exploit this by sending a network request to the affected endpoint to retrieve event details that are otherwise restricted. This results in a loss of confidentiality for calendar data. The issue is addressed in version 9.5.1.

Affected products

  • Concrete CMS Concrete CMS <= 9.5.0

Timeline

  • 2026-05-21: advisory: GitHub Advisory published
  • 2026-05-21: disclosed: NVD published date
  • 2026-05-21: patched: Version 9.5.1 released with fix

References

Related threats