CVE-2026-18121: Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}).

Published Sep 10, 2026
·
Updated

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/viewevent/{bID}/{occurrenceid}) does not verify that the caller is permitted to view the calendar that owns the requested event occurrence. The controller loads the occurrence directly from an attacker‑supplied, sequential identifier without confirming that it belongs to the calendar configured on the referenced block. An unauthenticated visitor who can render any public calendar block with lightbox properties enabled could therefore supply an arbitrary occurrence identifier and disclose event metadata — title, date, description, page link, and configured event attributes — from calendars they are not permitted to view. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks riodrwn for reporting.

Affected Software

1 affected component
Concrete CMS Concrete CMS<=9.5.2

Event History

Sep 10, 2026
CVE Published
via MITRE·11:10 PM
Data Sourced
via MITRE·11:10 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated visitor can exploit it if they can render any public calendar block that has lightbox properties enabled. No account or user interaction is required.

2

What information could be disclosed?

An attacker could disclose event metadata from calendars they are not permitted to view, including the event title, date, description, page link, and configured event attributes.

3

What does an attacker need to supply?

The attacker needs a public lightbox-enabled calendar block and an occurrence identifier. The affected endpoint loads occurrences using an attacker-supplied sequential identifier without confirming that the occurrence belongs to the calendar configured on the referenced block.

4

Are default public calendar deployments necessarily affected?

The provided information identifies exposure only where a public calendar block has lightbox properties enabled. It does not state whether lightbox properties are enabled by default.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203