Impact
An incorrect authorization mechanism in Drupal AI Agents permits forceful browsing, allowing an attacker to request protected URLs that should be inaccessible. The vulnerability is classified as CWE‑863 and can expose sensitive data or internal system information without proper authentication.
Affected Systems
All release versions of Drupal AI Agents from 0.0.0 through 1.1.4, from 1.2.0 through 1.2.5, and from 1.3.0 through 1.3.1 are vulnerable. No specific operating system or hardware prerequisites are noted, meaning any installation of those versions could be impacted.
Risk and Exploitability
The flaw can be triggered by modifying the requested URL, making the attack vector remote and not requiring any pre‑authentication. The EPSS score is reported as < 1 %, indicating a very low but non‑zero likelihood of exploitation. The CVSS score of 4.8 places the issue in the moderate severity range, and it is not listed in CISA KEV. Despite the low exploitation probability, the potential to bypass access controls and disclose confidential information warrants prompt remediation.
OpenCVE Enrichment