SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-18121

MEDIUM · CVSS 6.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Concrete CMS versions 9.5.2 and earlier are susceptible to an authorization bypass vulnerability that allows unauthenticated users to access event metadata from private calendars through a manipulated endpoint. This flaw enables attackers to disclose sensitive information, including event titles, dates, and descriptions, simply by supplying arbitrary identifiers. Organizations using affected versions of Concrete CMS, particularly those managing public calendar blocks, should prioritize patching this vulnerability to mitigate potential data exposure risks.

CVE
CVE-2026-18121
Severity
MEDIUM
CVSS
6.3
EPSS
0.25%

Original NVD Description

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calendar that owns the requested event occurrence. The controller loads the occurrence directly from an attacker‑supplied, sequential identifier without confirming that it belongs to the calendar configured on the referenced block. An unauthenticated visitor who can render any public calendar block with lightbox properties enabled could therefore supply an arbitrary occurrence identifier and disclose event metadata — title, date, description, page link, and configured event attributes — from calendars they are not permitted to view. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.