CVE-2026-18121 | Concrete CMS up to 9.5.2 Frontend Calendar Lightbox Endpoint /ccm/calendar/view_event bID/occurrence_id authorization
A vulnerability has been found in Concrete CMS up to 9.5.2 and classified as problematic. This issue affects some unknown processing of the file /ccm/calendar/view_event of the component Frontend Calendar Lightbox Endpoint. This manipulation of the argument bID/occurrence_id causes authorization bypass.
This vulnerability is tracked as CVE-2026-18121. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More