Description
Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing.

This issue affects Date iCal: from 0.0.0 before 4.0.15.
Published: 2026-05-19
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization flaw in the Drupal Date iCal module permits forceful browsing, allowing attackers to access calendar data that should be restricted. This vulnerability can lead to unintended exposure of potentially sensitive scheduling information and may compromise user privacy. The weakness is classified as Missing Authorization, indicating that the system does not properly verify that a user is permitted to view the requested resource.

Affected Systems

The Drupal Date iCal module, versions starting at 0.0.0 and any release before 4.0.15, is affected. Users running these unpatched releases should assess whether the module is in use and whether calendar data is publicly exposed.

Risk and Exploitability

No EPSS score is currently available, and the vulnerability is not listed in CISA's KEV catalog. Because the flaw is a straightforward lack of access checks, the likelihood of exploitation is high in environments where the module is deployed and exposed. An attacker would simply request known or guessed iCal URLs without authentication, and if the system does not enforce authorization, sensitive data would be returned. The impact is limited to confidentiality breach rather than a full system compromise.

Generated by OpenCVE AI on May 19, 2026 at 23:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Date iCal module to version 4.0.15 or later
  • Enforce proper authorization checks on all iCal endpoints to prevent forceful browsing
  • Restrict or remove publicly accessible paths that expose calendar data

Generated by OpenCVE AI on May 19, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 19 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.
Title Date iCal - Critical - Information disclosure - SA-CONTRIB-2026-037
Weaknesses CWE-862
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-05-19T22:29:50.850Z

Reserved: 2026-05-13T16:55:31.986Z

Link: CVE-2026-8495

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-19T23:16:59.117

Modified: 2026-05-19T23:16:59.117

Link: CVE-2026-8495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-19T23:30:05Z

Weaknesses