Description
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in Drupal core enables forceful browsing, allowing an attacker to access web pages or resources that should be protected without proper credentials. This vulnerability can expose confidential content or administrative data, compromising the confidentiality of the installed site. The weakness is identified as an improper authorization flaw (CWE-862).

Affected Systems

Drupal core versions from 0.0.0 up to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, and all releases of 11.0.*, 11.1.*, and 11.2.* are vulnerable.

Risk and Exploitability

The CVE is classified as moderately critical and is not listed in CISA's KEV catalog. No EPSS score is available, indicating that the exploitation likelihood is not quantifiable in the current dataset. The likely attack vector is forceful browsing accessed through web requests to protected resources, with the attacker needing only to discover a URL that is not properly gated by Drupal's permission system.

Generated by OpenCVE AI on August 26, 2026 at 00:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drupal core to a fixed version (10.6.14 or newer, 11.3.15 or newer, 11.4.5 or newer, etc.)
  • Review and tighten permission settings to ensure that only authorized roles have access to sensitive content
  • Audit remaining access paths or use web application firewalls to block unauthorized requests

Generated by OpenCVE AI on August 26, 2026 at 00:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 26 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal drupal Core
Vendors & Products Drupal
Drupal drupal Core

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
Title Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
Weaknesses CWE-862
References

Subscriptions

Drupal Drupal Core
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-08-25T22:22:27.131Z

Reserved: 2026-07-15T19:41:24.786Z

Link: CVE-2026-15916

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T23:16:56.320

Modified: 2026-08-25T23:16:56.320

Link: CVE-2026-15916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T01:45:03Z

Weaknesses