Impact
A missing authorization check in Drupal core enables forceful browsing, allowing an attacker to access web pages or resources that should be protected without proper credentials. This vulnerability can expose confidential content or administrative data, compromising the confidentiality of the installed site. The weakness is identified as an improper authorization flaw (CWE-862).
Affected Systems
Drupal core versions from 0.0.0 up to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, and all releases of 11.0.*, 11.1.*, and 11.2.* are vulnerable.
Risk and Exploitability
The CVSS score is 4.2, indicating a moderately critical level of risk, and the vulnerability is not listed in CISA's KEV catalog. The EPSS score is < 1%, indicating a very low exploitation probability. The likely attack vector is forceful browsing accessed through web requests to protected resources, with the attacker needing only to discover a URL that is not properly gated by Drupal's permission system.
OpenCVE Enrichment