Impact
Drupal Role Delegation exposes a privilege‑defined with unsafe actions flaw that allows an attacker to elevate privileges. The weakness permits a user to gain higher permissions than intended, potentially compromising the confidentiality and integrity of the site. The vulnerability is classified as CWE‑267, a privilege‑management weakness.
Affected Systems
Drupal Role Delegation is affected in all releases from 1.3.0 up to, but not including, 1.5.0. The module should be identified by the standard Drupal naming for the Role Delegation project. No specific operating system versions are referenced.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk, while the EPSS score of less than 1% suggests a very low probability of exploitation at the time of reporting. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description, involves accessing the role delegation configuration through the Drupal administrative interface or leveraging existing authenticated roles to alter role assignments. Exploitation would require the attacker to determine which roles are delegable and then manipulate the hierarchy, but no explicit prerequisites such as administrative or multi‑factor authentication bypass are documented.
OpenCVE Enrichment