Description
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
Published: 2026-07-10
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization check in Drupal LocalGov Workflows. This check allows forceful browsing, enabling an attacker to view data or resources that should be protected. The result can be the disclosure of sensitive information, compromising confidentiality. The flaw is categorized as CWE-862, representing missing or insufficient authorization.

Affected Systems

Drupal LocalGov Workflows is the affected product, with versions ranging from 0.0.0 to 1.6.0 listed as impacted. No other vendors or products are referenced by the CNA.

Risk and Exploitability

The EPSS score is less than 1%, indicating a very low probability of exploitation. The flaw manifests as unauthorized browsing, so the most likely attack vector is a remote web interface, enabling both authenticated and unauthenticated users to forcefully access protected resources. The advisory labels the issue as moderately critical, and the flaw is not listed in CISA KEV. An attacker who can exploit this missing authorization may retrieve confidential data or use the information to further compromise the system.

Generated by OpenCVE AI on July 29, 2026 at 09:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available official patch or upgrade Drupal LocalGov Workflows to the latest version when it is released.
  • Enforce strict access control permissions to restrict unauthorized browsing of sensitive resources.
  • Monitor web server logs for patterns of forceful browsing and configure firewall or IDS/IPS rules accordingly.

Generated by OpenCVE AI on July 29, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal localgov Workflows
Vendors & Products Drupal
Drupal localgov Workflows

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
Title LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039
Weaknesses CWE-862
References

Subscriptions

Drupal Localgov Workflows
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-14T14:35:01.464Z

Reserved: 2026-06-03T15:41:14.341Z

Link: CVE-2026-10768

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:00:15Z

Weaknesses