Description
Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.
Published: 2026-07-10
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a missing authorization flaw that permits forceful browsing, allowing attackers to access restricted content and configuration settings that should be protected. It is identified by CWE‑862, underlining the absence of proper access control enforcement. An attacker who can discover URLs or resources may retrieve sensitive information or execute privileged actions without proper authentication, potentially exposing confidential data.

Affected Systems

The flaw affects the Drupal \"Examples for Developers\" module in all releases from 0.0.0 through 4.0.6. Users deploying any of these versions may be exposed to unauthorized access to module content and management functionality.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability has not been listed in the CISA KEV catalog, indicating that no large‑scale exploits are currently documented. The attack vector is most likely a standard HTTP request to non‑existent or protected pages (forceful browsing). The CVSS score of 3.3 indicates low severity, but the lack of authentication in the affected module means any user with network access to the Drupal instance could potentially exploit the flaw if the module is installed and accessible.

Generated by OpenCVE AI on July 31, 2026 at 12:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Examples for Developers module to the latest available version after a patch has been released
  • If an update is not yet released, remove or disable the Examples for Developers module until a patch is provided
  • After disabling the module, review site permissions to ensure no other components expose similar unauthenticated access paths

Generated by OpenCVE AI on July 31, 2026 at 12:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal examples For Developers
Vendors & Products Drupal
Drupal examples For Developers

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.
Title Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044
Weaknesses CWE-862
References

Subscriptions

Drupal Examples For Developers
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T18:09:37.596Z

Reserved: 2026-06-10T16:26:55.928Z

Link: CVE-2026-11909

cve-icon Vulnrichment

Updated: 2026-07-13T16:40:52.115Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:00:10Z

Weaknesses