Description
Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.
Published: 2026-07-10
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect authorization mechanism in Drupal AI Agents permits forceful browsing, allowing an attacker to request protected URLs that should be inaccessible. The vulnerability is classified as CWE‑863 and can expose sensitive data or internal system information without proper authentication.

Affected Systems

All release versions of Drupal AI Agents from 0.0.0 through 1.1.4, from 1.2.0 through 1.2.5, and from 1.3.0 through 1.3.1 are vulnerable. No specific operating system or hardware prerequisites are noted, meaning any installation of those versions could be impacted.

Risk and Exploitability

The flaw can be triggered by modifying the requested URL, making the attack vector remote and not requiring any pre‑authentication. The EPSS score is reported as < 1 %, indicating a very low but non‑zero likelihood of exploitation. The CVSS score of 4.8 places the issue in the moderate severity range, and it is not listed in CISA KEV. Despite the low exploitation probability, the potential to bypass access controls and disclose confidential information warrants prompt remediation.

Generated by OpenCVE AI on July 31, 2026 at 12:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drupal AI Agents to a release newer than 1.3.1 to receive the authorization fix.
  • Monitor logs for unauthorized access attempts targeting protected resources.
  • Apply additional URL filtering or access control rules at the web server or application layer to block unauthorized requests to sensitive resources.

Generated by OpenCVE AI on July 31, 2026 at 12:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal ai Agents
Vendors & Products Drupal
Drupal ai Agents

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.
Title AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057
Weaknesses CWE-863
References

Subscriptions

Drupal Ai Agents
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T17:59:44.338Z

Reserved: 2026-06-24T18:00:10.666Z

Link: CVE-2026-13237

cve-icon Vulnrichment

Updated: 2026-07-13T16:26:43.063Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:00:10Z

Weaknesses