Description
Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.
Published: 2026-07-10
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect authorization check in the Advanced Content Feedback module of Drupal, enabling forceful browsing of content. An attacker can programmatically request feedback objects that they are not permitted to view, allowing exposure of potentially sensitive information. The flaw is formally classified as an Insecure Direct Object Reference (CWE‑863).

Affected Systems

The vulnerability affects the Drupal Advanced Content Feedback (aka admin_feedback) module. Versions 0.0.0 through 2.8.0 are affected. Any site that has installed this module within those releases is potentially vulnerable until it is updated beyond 2.8.0.

Risk and Exploitability

Because the exploit requires only an HTTP request to an existing feedback object, the threat vector is likely remote through the web interface. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, meaning no mass‑production exploits are known. Nevertheless, the lack of a proper authorization check means that any authenticated or unauthenticated user who can determine a valid object identifier could access data they should not. The CVSS score is 3.1, and based on the description it is inferred that the confidentiality impact could be substantial on a pod or shared hosting environment.

Generated by OpenCVE AI on July 31, 2026 at 12:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Advanced Content Feedback than 2.8.0 or apply the official patch from SA‑CONTRIB‑2026‑052.
  • Verify that the module’s administrative permissions restrict access only to authorized roles and adjust role permissions to match the organization’s security policy, addressing the Insecure Direct Object Reference (CWE‑863).
  • If an upgrade cannot be performed immediately, disable direct URLs that expose feedback data or remove the module entirely until a fix is applied.

Generated by OpenCVE AI on July 31, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal advanced Content Feedback (aka Admin Feedback)
Vendors & Products Drupal
Drupal advanced Content Feedback (aka Admin Feedback)

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.
Title Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access bypass / Insecure Direct Object Reference (IDOR) - SA-CONTRIB-2026-052
Weaknesses CWE-863
References

Subscriptions

Drupal Advanced Content Feedback (aka Admin Feedback)
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T18:04:11.237Z

Reserved: 2026-06-24T18:00:05.703Z

Link: CVE-2026-13232

cve-icon Vulnrichment

Updated: 2026-07-13T16:32:56.967Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:00:10Z

Weaknesses