Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
Published: 2026-08-25
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass via Alternate Path
Action: Apply Patch
AI Analysis

Impact

An attacker can bypass authentication by using an alternate path or channel within Drupal Internationalization Single Sign-On. This flaw allows unauthorized users to obtain successful login tokens or access privileges that they should not possess. The weakness is a typical authentication bypass (CWE-288) which compromises the confidentiality and integrity of user sessions and potentially any data accessed thereafter.

Affected Systems

All Drupal Internationalization Single Sign-On installations from version 0.0.0 up to and including 1.8.0 are affected. The vulnerability exists in the module’s handling of alternate sign‑on paths.

Risk and Exploitability

The CVSS score is 9.8, and the EPSS score is < 1%, indicating a low exploitation probability; the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an alternate authentication URL that an attacker can construct and use to obtain a valid session. The exploitation requires only access to the application’s domain and knowledge of the module’s URL structure. The severity is potentially high due to the complete bypass of authentication controls.

Generated by OpenCVE AI on August 26, 2026 at 17:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Drupal Internationalization Single Sign-On module to the latest patch or a version newer than 1.8.0.
  • If the module is not required for site operation, disable or uninstall it until a fix is applied.
  • Audit SSO configurations and user accounts to ensure that only authorized users can access authenticated services and monitor for suspicious login patterns.

Generated by OpenCVE AI on August 26, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal internationalization Single Sign-on
Vendors & Products Drupal
Drupal internationalization Single Sign-on

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
Title Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081
Weaknesses CWE-288
References

Subscriptions

Drupal Internationalization Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-08-26T15:23:15.811Z

Reserved: 2026-07-22T17:06:41.738Z

Link: CVE-2026-16639

cve-icon Vulnrichment

Updated: 2026-08-26T15:23:07.057Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-25T23:16:56.673

Modified: 2026-08-28T15:29:44.967

Link: CVE-2026-16639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:34:04Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel