PT-2026-40839 · Drupal · Date Ical

Dave Long

+4

·

Published

2026-05-13

·

Updated

2026-06-01

·

CVE-2026-8495

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Date iCal versions 0.0.0 through 4.0.14
Description A missing authorization issue in the Date iCal module, which exports entity date fields as iCal feeds, allows forceful browsing. The module fails to sufficiently check entity or field access and does not properly sanitize user inputs during the generation of iCal feeds. These routes are accessible to all anonymous users without requiring any configuration.
Recommendations Update to version 4.0.15.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-8495
DRUPAL-CONTRIB-2026-037

Affected Products

Date Ical