Description
Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.
Published: 2026-08-25
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential system compromise due to a moderate severity vulnerability in Drupal Development Environment
Action: Assess Impact
AI Analysis

Impact

A critical vulnerability exists in the Drupal Development Environment component. The description is limited, but it indicates that the vulnerability affects all versions of the component. The lack of details suggests that exploitation could provide an attacker with unauthorized access or the ability to execute code within the development environment, potentially compromising the host system. The likely attack vector is not explicitly stated, but given the nature of development environments, it is inferred that a remote attacker could exploit a web‑based interface or local privilege escalation may also be possible.

Affected Systems

The affected product is Drupal Development Environment across all listed versions, denoted as *.* in the advisory. No specific version ranges are provided, leaving uncertainty about which releases are impacted.

Risk and Exploitability

The CVSS score is 5.7 and the EPSS score is < 1%, indicating a moderate severity and low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Without a remediation package, the risk remains largely theoretical, but the potential impact could be high if the development environment is exposed to untrusted users or the internet. Attackers may target the environment through typical web‑application vectors or local privilege escalation pathways.

Generated by OpenCVE AI on August 26, 2026 at 21:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the installed Drupal Development Environment version and confirm whether it is listed as affected
  • If an affected version is in use, update to the latest Drupal release or remove the Development Environment feature entirely
  • Restrict network access to the development environment by using firewall rules or VPN to limit exposure to trusted users
  • Implement monitoring of web traffic and application logs for suspicious activity

Generated by OpenCVE AI on August 26, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal development Environment
Vendors & Products Drupal
Drupal development Environment

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.
Title Development Environment - Critical - Unsupported - SA-CONTRIB-2026-089
References

Subscriptions

Drupal Development Environment
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-08-26T18:54:39.563Z

Reserved: 2026-07-08T15:45:02.189Z

Link: CVE-2026-15088

cve-icon Vulnrichment

Updated: 2026-08-26T18:54:32.336Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-25T23:16:54.810

Modified: 2026-08-28T15:29:44.967

Link: CVE-2026-15088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:34:13Z

Weaknesses
  • CWE-20

    Improper Input Validation