CVE-2026-68527
Deferred Deferred - Pending Action

Authorization Bypass in Concrete CMS Calendar Events

Vulnerability report for CVE-2026-68527, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: ConcreteCMS

Description

Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the calendar identifier supplied in the request rather than the calendar owning the targeted event occurrence. A user with the "Add Event" permission on a single calendar could read and overwrite events on calendars they were not permitted to access, and could delete an event's original local occurrence. Publishing the injected version to the live calendar, which demotes the previously approved version, additionally required the actor's approve_calendar_event workflow rights or an auto-approving workflow. The Concrete CMS Security Team gave this a rank of 5.9 with CVSS 4.0 vectorΒ CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
concrete_cms concrete_cms From 8.3.0 (inc) to 9.5.2 (inc)
concrete_cms concrete_cms 9.5.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Concrete CMS versions 8.3.0 through 9.5.2 have an authorization bypass in the Calendar event edit dialog. The system checked permissions against the calendar identifier in the request instead of the calendar owning the targeted event. This allowed users with 'Add Event' permission on one calendar to read, overwrite, or delete events on other calendars they shouldn't access.

Impact Analysis

An attacker with limited permissions could access, modify, or delete events on calendars they are not authorized to view. This could lead to unauthorized changes in event data, data loss, or misinformation being published if the attacker exploits workflow rights to publish changes.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive event data, potentially violating GDPR (data protection) or HIPAA (health information privacy) requirements. Unauthorized changes to event records may result in non-compliance with data integrity and access control regulations.

Mitigation Strategies

Upgrade Concrete CMS to version 9.5.3 or later to address the authorization bypass vulnerability in the Calendar event edit dialog.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68527. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart