CVE-2026-68526
Analyzed Analyzed - Analysis Complete

Concrete CMS Calendar Event Duplication via Missing CSRF Token Validation

Vulnerability report for CVE-2026-68526, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-25

Assigner: ConcreteCMS

Description

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canAccess() and the per-resource canAddCalendarEvent() permission, so a crafted cross-site request could cause an authenticated user with add-event permission to create duplicate CalendarEvents and CalendarEventVersions records under their own authority.Β The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N.Β Thanks Winston CrookerΒ for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-25
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
concretecms concrete_cms to 9.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS before 9.5.3 had a vulnerability where an anti-CSRF token was not validated in the Calendar event duplicate dialog controller. This allowed an authenticated user with add-event permission to create duplicate calendar events without proper authorization checks.

Detection Guidance

This vulnerability involves a missing anti-CSRF token validation in Concrete CMS versions before 9.5.3. To detect it, check if your Concrete CMS version is below 9.5.3 by running: grep -r 'Version' /path/to/concretecms/config/site.php or check the admin dashboard. If vulnerable, inspect the file concrete/controllers/dialog/event/duplicate.php for the submit() action and verify if anti-CSRF token checks are missing.

Impact Analysis

An attacker could exploit this to create duplicate calendar events under the victim's account, potentially leading to confusion, data integrity issues, or unauthorized actions if combined with other vulnerabilities.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized data modifications, potentially violating integrity requirements in GDPR or HIPAA. However, no direct compliance impact is specified in the provided context.

Mitigation Strategies

Upgrade Concrete CMS to version 9.5.3 or later to address the anti-CSRF token validation issue in the Calendar event duplicate dialog controller.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68526. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart