Description
Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas: from 0.0.0 before 1.0.4.
Published: 2026-02-04
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Forceful Browsing – unauthorized access to restricted resources
Action: Patch
AI Analysis

Impact

This vulnerability is an incorrect authorization flaw that allows attackers to perform forceful browsing of content that should be restricted. By directly requesting URLs that the system should protect, an unauthorized user can access files, pages, or resources that are meant to be hidden from unauthenticated or non‑privileged users. The weakness is identified as CWE‑863, indicating a failure of policy enforcement in the authorization mechanism. The impact is loss of confidentiality for protected data and potential damage to the integrity and trustworthiness of the application.

Affected Systems

Drupal Canvas versions before 1.0.4 are affected. Any deployment using Drupal Canvas 0.0.0 up to 1.0.3 is vulnerable.

Risk and Exploitability

The CVSS score of 4.8 classifies this flaw as medium severity, and the EPSS score, which is below 1%, indicates a low probability of exploitation. The vulnerability is not currently cataloged in the CISA Known Exploited Vulnerabilities database. The likely attack vector is a remote HTTP request to unauthorized resources, inferred from the forceful browsing behavior described. In practice, an attacker can construct URLs to restricted content; if the application fails to enforce the correct access controls (CWE‑863), the content is returned to the requester without authentication or authorization. No additional prerequisites are listed, implying that the vulnerability can be leveraged by anyone who can access the web interface.

Generated by OpenCVE AI on April 17, 2026 at 23:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drupal Canvas to version 1.0.4 or later, where the access check has been corrected.
  • Verify that access control rules for Canvas content are properly configured to restrict roles and permissions.
  • As a temporary workaround, configure the web server or application firewall to block direct access to known Canvas endpoints for unauthenticated users, such as by adding .htaccess restrictions or IP-based rules.

Generated by OpenCVE AI on April 17, 2026 at 23:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 11 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal Canvas Project
Drupal Canvas Project drupal Canvas
CPEs cpe:2.3:a:drupal_canvas_project:drupal_canvas:*:*:*:*:*:drupal:*:*
Vendors & Products Drupal Canvas Project
Drupal Canvas Project drupal Canvas

Thu, 05 Feb 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal canvas
Vendors & Products Drupal
Drupal canvas

Wed, 04 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas: from 0.0.0 before 1.0.4.
Title Drupal Canvas - Moderately critical - Access bypass - SA-CONTRIB-2026-006
Weaknesses CWE-863
References

Subscriptions

Drupal Canvas
Drupal Canvas Project Drupal Canvas
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-02-04T21:21:35.681Z

Reserved: 2026-01-28T17:01:08.406Z

Link: CVE-2026-1553

cve-icon Vulnrichment

Updated: 2026-02-04T21:21:32.635Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-04T21:15:59.267

Modified: 2026-02-11T19:19:03.170

Link: CVE-2026-1553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T23:15:30Z

Weaknesses