Description
Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the calendar identifier supplied in the request rather than the calendar owning the targeted event occurrence. A user with the "Add Event" permission on a single calendar could read and overwrite events on calendars they were not permitted to access, and could delete an event's original local occurrence. Publishing the injected version to the live calendar, which demotes the previously approved version, additionally required the actor's approve_calendar_event workflow rights or an auto-approving workflow. The Concrete CMS Security Team gave this a rank of 5.9 with CVSS 4.0 vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Published: 2026-09-10
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Patch
AI Analysis

Impact

Concrete CMS versions 8.3.0 through 9.5.2 contain an authorization bypass flaw in the Calendar event edit dialog. The dialog uses a user supplied calendar identifier instead of the calendar that owns the targeted event, allowing a user who has the basic "Add Event" permission on one calendar to see, modify, or delete events on other calendars they should not be able to access. This violates expected authorization boundaries and can lead to unauthorized disclosure or tampering of calendar data, as well as disruption of scheduled events.

Affected Systems

The vulnerability affects Concrete CMS installations running any software version from 8.3.0 up to and including 9.5.2. No earlier or later releases are identified as vulnerable.

Risk and Exploitability

With a CVSS score of 5.9 and a vector indicating a network attack with low complexity and high required privileges, the threat is moderate. The exploit requires permission on a calendar; such a user can then access the edit dialog and supply a different calendar ID to manipulate events elsewhere. No public exploits are currently documented and the EPSS score is unavailable, but the vulnerability is listed in the vendor’s documentation and should be considered mitigable through a patch, rather than relying on workarounds.

Generated by OpenCVE AI on September 10, 2026 at 23:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Concrete CMS to the latest version (9.5.3 or newer) where the authorization check on the owned calendar has been corrected.
  • If an immediate upgrade is not possible, remove or restrict the "Add Event" permission from users who do not need to manage events on other calendars and audit permissions to ensure only authorized users have broader access.
  • Add server‑side validation to confirm that the calendar ID supplied in the edit request matches the calendar owning the target event, preventing cross‑calendar modifications.

Generated by OpenCVE AI on September 10, 2026 at 23:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the calendar identifier supplied in the request rather than the calendar owning the targeted event occurrence. A user with the "Add Event" permission on a single calendar could read and overwrite events on calendars they were not permitted to access, and could delete an event's original local occurrence. Publishing the injected version to the live calendar, which demotes the previously approved version, additionally required the actor's approve_calendar_event workflow rights or an auto-approving workflow. The Concrete CMS Security Team gave this a rank of 5.9 with CVSS 4.0 vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Title Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-10T18:29:04.125Z

Reserved: 2026-07-30T18:04:50.762Z

Link: CVE-2026-68527

cve-icon Vulnrichment

Updated: 2026-09-10T18:29:00.874Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T19:17:32.423

Modified: 2026-09-10T19:58:20.507

Link: CVE-2026-68527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:15:15Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key