Description
Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canAccess() and the per-resource canAddCalendarEvent() permission, so a crafted cross-site request could cause an authenticated user with add-event permission to create duplicate CalendarEvents and CalendarEventVersions records under their own authority. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Creation of Calendar Events via CSRF
Action: Apply Patch
AI Analysis

Impact

Concrete CMS versions prior to 9.5.3 contain a cross‑site request forgery flaw in the Calendar event duplicate dialog controller, where the submit action fails to validate an anti‑CSRF token while only checking generic access permissions. This weakness, identified as CWE‑352, allows an attacker to craft a request that causes an authenticated user with add‑event rights to duplicate calendar events and event version records under the user’s own authority. The resulting damage is limited to the creation of duplicate entries; there is no escalation to higher privileges or arbitrary code execution.

Affected Systems

Any installation of the open‑source Concrete CMS platform running a version earlier than 9.5.3 is vulnerable. The flaw affects the Calendar event duplicate dialog controller in all pre‑9.5.3 releases, regardless of individual site configuration, as no further version granularity is specified.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, with network access, low complexity, and no user interaction required beyond a normal login. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a crafted CSRF request that a web browser loads while an authorized user with permission to add events is logged in, thereby causing the site to duplicate an existing event.

Generated by OpenCVE AI on September 21, 2026 at 03:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to version 9.5.3 or later
  • Verify that CSRF token validation is active in the Calendar event duplicate dialog controller
  • Restrict the canAddCalendarEvent permission to users who truly need it, reducing the opportunity for unintended duplication

Generated by OpenCVE AI on September 21, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canAccess() and the per-resource canAddCalendarEvent() permission, so a crafted cross-site request could cause an authenticated user with add-event permission to create duplicate CalendarEvents and CalendarEventVersions records under their own authority. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Title Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controller
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-14T13:00:32.542Z

Reserved: 2026-07-30T18:04:50.762Z

Link: CVE-2026-68526

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:48.562Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T20:17:21.653

Modified: 2026-09-25T20:41:17.633

Link: CVE-2026-68526

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:00:13Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)