CVE
CVE-2026-8495
This module enables you to export entity date fields as iCal feeds.The module doesn't sufficiently check entity or field access or sanitize user inputs when generating iCal feeds.This vulnerabilit...
This module enables you to export entity date fields as iCal feeds.
The module doesn't sufficiently check entity or field access or sanitize user inputs when generating iCal feeds.
This vulnerability is not mitigated by any permission, the routes are accessible to all anonymous users with no configuration required.
Package Versions Affected
Package Version
patch Availability
No items found.
Automatically patch vulnerabilities without upgrading
Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request
CVSS Version
Severity
Base Score
CVSS Version
Score Vector

C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

C
H
U
0
-

C
H
U
-
Related Resources
No items found.
References
https://www.drupal.org/sa-contrib-2026-037
