CVE-2026-8495: Date Ical Project Date Ical

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.

Affected products

Published 2026-05-19. Last modified 2026-07-23.