Description
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.
Published: 2026-07-10
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Drupal AI implements a missing authorization check that allows an unauthenticated or unauthorized user to request any resource handled by the module. This flaw can expose content that should be protected, thereby compromising confidentiality. It is classified as a missing authorization weakness (CWE‑862).

Affected Systems

Any instance of the Drupal AI module that is running a version from 0.0.0 through 1.2.17, 1.3.0 through 1.3.8, or 1.4.0 through 1.4.3 is affected. The vulnerability resides in the AI (Artificial Intelligence) component distributed by Drupal and is not limited to any specific submodule or database layer.

Risk and Exploitability

The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA KEV. Its CVSS score of 3.3 reflects low severity, but the flaw still permits an attacker to read protected content via forceful browsing. The likely attack vector is remote; an attacker only needs to craft requests to the vulnerable endpoints. Although widespread exploitation is unlikely, sites exposing the module to the internet could attract attempts.

Generated by OpenCVE AI on July 31, 2026 at 12:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Drupal AI module to a version that is not listed as vulnerable, such as the latest release available from the Drupal AI repository.
  • If the AI (Artificial Intelligence) module is not required for your site's functionality, disable or uninstall it completely.
  • Apply Web Application Firewall or similar access controls to block unauthorized requests targeting the AI module endpoints until a patch is applied.

Generated by OpenCVE AI on July 31, 2026 at 12:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal artificial Intelligence
Vendors & Products Drupal
Drupal artificial Intelligence

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.
Title AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055
Weaknesses CWE-862
References

Subscriptions

Drupal Artificial Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T18:06:50.932Z

Reserved: 2026-06-24T18:00:08.720Z

Link: CVE-2026-13235

cve-icon Vulnrichment

Updated: 2026-07-13T16:34:31.855Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:00:10Z

Weaknesses