XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2026-007 |
|
History
Wed, 04 Feb 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2. | |
| Title | Central Authentication System (CAS) Server - Less critical - XML Element Injection - SA-CONTRIB-2026-007 | |
| Weaknesses | CWE-91 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2026-02-04T20:26:38.850Z
Reserved: 2026-01-28T17:01:09.595Z
Link: CVE-2026-1554
No data.
Status : Received
Published: 2026-02-04T21:15:59.427
Modified: 2026-02-04T21:15:59.427
Link: CVE-2026-1554
No data.
OpenCVE Enrichment
No data.
Weaknesses