PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18121 Concrete CMS CVE debrief

An authorization bypass vulnerability exists in Concrete CMS versions 9.5.2 and below, allowing unauthenticated visitors to disclose event metadata from calendars they are not permitted to view. The vulnerability is due to the frontend calendar lightbox endpoint not verifying caller permissions. A CVSS v4.0 score of 6.3 was given with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N.

Vendor
Concrete CMS
Product
Unknown
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Defenders responsible for Concrete CMS installations, particularly those with public calendar blocks enabled, should assess exposure and prioritize patching or restricting access to vulnerable endpoints.

Why it matters

Defenders should care about CVE-2026-18121 because it allows unauthorized disclosure of event metadata in Concrete CMS installations, particularly those with public calendar blocks enabled. The vulnerability requires verification of affected versions, inventory checks, and prompt remediation to prevent potential data exposure.

  • Potential disclosure of sensitive event metadata
  • Increased risk of unauthorized access to calendar data
  • Need for verification of vulnerable Concrete CMS installations
  • Priority for patching or mitigating vulnerable endpoints

Technical summary

The frontend calendar lightbox endpoint in Concrete CMS versions 9.5.2 and below does not verify caller permissions, allowing unauthenticated visitors to disclose event metadata from calendars they are not permitted to view. This vulnerability, reported as an authorization bypass (IDOR), enables attackers to supply an arbitrary occurrence identifier and access event metadata, including title, date, description, page link, and configured event attributes, from calendars they are not permitted to view. The vulnerability was assigned a CVSS v4.0 score of 6.3.

Defensive priority

Defenders should prioritize verifying and patching vulnerable Concrete CMS installations, restricting access to calendar endpoints, and monitoring for unauthorized access attempts.

Recommended defensive actions

  • Verify and patch vulnerable Concrete CMS installations
  • Restrict access to calendar endpoints
  • Monitor for unauthorized access attempts
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Plan vendor-supported updates through normal change control

Evidence notes

The vulnerability was reported by riodrwn and assigned a CVSS v4.0 score of 6.3 by the Concrete CMS security team. The NVD entry is currently Deferred. Evidence is limited to public CVE Program and NVD records. Defenders should verify affected Concrete CMS installations and review official advisories for further details. Limited source information suggests that an unauthenticated visitor could disclose event metadata, including title, date, description, page link, and configured event attributes, from calendars they are not permitted

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18121 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18121

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18121 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18121

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://documentation.concretecms.org/developers/introduction/version-history/953-release-notes

    ff5b8ace-8b95-4078-9743-eac1ca5451de

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.