Impact
A missing authorization check in Drupal core enables forceful browsing, allowing an attacker to access web pages or resources that should be protected without proper credentials. This vulnerability can expose confidential content or administrative data, compromising the confidentiality of the installed site. The weakness is identified as an improper authorization flaw (CWE-862).
Affected Systems
Drupal core versions from 0.0.0 up to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, and all releases of 11.0.*, 11.1.*, and 11.2.* are vulnerable.
Risk and Exploitability
The CVE is classified as moderately critical and is not listed in CISA's KEV catalog. No EPSS score is available, indicating that the exploitation likelihood is not quantifiable in the current dataset. The likely attack vector is forceful browsing accessed through web requests to protected resources, with the attacker needing only to discover a URL that is not properly gated by Drupal's permission system.
OpenCVE Enrichment