CVE-2026-68526
Last modified
CVE-2026-68526 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canAccess() and the per-resource canAddCalendarEvent() permission, so a crafted cross-site request could cause an authenticated user with add-event permission to create duplicate CalendarEvents and CalendarEventVersions records under their own authority. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canAccess() and the per-resource canAddCalendarEvent() permission, so a crafted cross-site request could cause an authenticated user with add-event permission to create duplicate CalendarEvents and CalendarEventVersions records under their own authority. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.3 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Winston Crooker for reporting.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Concrete CMS | Concrete CMS | 9.5.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-68526?
How severe is CVE-2026-68526?
How do I fix CVE-2026-68526?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68516OpenEXR is the reference implementation and specification fo…6.5
- CVE-2026-68517Glances is an open-source system cross-platform monitoring t…6.5
- CVE-2026-68518Glances is an open-source system cross-platform monitoring t…8.8
- CVE-2026-68519Glances is an open-source system cross-platform monitoring t…7.1
- CVE-2026-68520Glances is an open-source system cross-platform monitoring t…5.3
- CVE-2026-68525Incorrect Authorization vulnerability in Apache Tomcat's FOR…9.1
- CVE-2026-68527Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to …5.9
- CVE-2026-68528Concrete CMS RSS Displayer block below version 9.5.3 render…6
- CVE-2026-68529Concrete CMS 9.0.0 through 9.5.2 was missing an authorizatio…2.1
- CVE-2026-6853Improper restriction of excessive authentication attempts vu…9.8
- CVE-2026-68530Concrete CMS 9 through 9.5.2 did not perform an authorizatio…2.1
- CVE-2026-68531Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard…2.1
Are you affected by CVE-2026-68526?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
