CVE-2026-68526: Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplicate dialog controller

Published Sep 11, 2026
·
Updated

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canAccess() and the per-resource canAddCalendarEvent() permission, so a crafted cross-site request could cause an authenticated user with add-event permission to create duplicate CalendarEvents and CalendarEventVersions records under their own authority. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.

Affected Software

1 affected component
Concrete CMS Concrete CMS<9.5.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Concrete CMS to a version that resolves this vulnerability.

    Fixed in 9.5.3
  2. Compensating control

    If immediate upgrade is not possible, mitigate CSRF by restricting cross-site requests to the Concrete CMS instance (e.g., ensure the application uses/validates anti-CSRF tokens for the Calendar event duplicate dialog controller) and limit access to the endpoint so only trusted users from legitimate sessions can reach it.

Event History

Sep 11, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

An authenticated Concrete CMS user who has access to the Calendar duplicate dialog and permission to add calendar events can be targeted. The resulting duplicate events and event versions are created under that user's authority.

2

What does an attacker need to exploit it?

The attacker needs to induce a qualifying authenticated user to submit a crafted cross-site request. No attacker authentication or special privileges are required, but user interaction is required.

3

Are default permissions enough for exploitation?

No. The affected submit action checks both canAccess() and the per-resource canAddCalendarEvent() permission, so the targeted user must have permission to add calendar events.

4

What is the impact if exploitation succeeds?

The attacker can cause duplicate CalendarEvents and CalendarEventVersions records to be created. The provided CVSS v4.0 vector indicates low integrity impact and no confidentiality or availability impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203