CVE-2026-8205: Concrete CMS is vulnerable to authorization bypass in the Calendar Block
(updated )
Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted event details being disclosed.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-8205 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →