Concrete CMS Calendar Event Frontend Dialog Authorization Bypass Vulnerability Allowing Cross-Calendar Data Disclosure

Vulnerability

An authorization bypass vulnerability has been identified in the Calendar Event Frontend Dialog of Concrete CMS versions through 9.5.0. This vulnerability can lead to unauthorized access to private calendar data by exploiting a public calendar block as a pivot point. The issue allows cross-calendar data disclosure, where private calendar information can be accessed through a publicly shared calendar.

Impact

Exploitation of this vulnerability could result in unauthorized access to private calendar data, allowing cross-calendar data disclosure.

Added: May 21, 2026, 9:26 PM
Updated: May 21, 2026, 9:26 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
6.8
remediation
7.7
relevance
9.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.