Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can bypass authentication by using an alternate path or channel within Drupal Internationalization Single Sign-On. This flaw allows unauthorized users to obtain successful login tokens or access privileges that they should not possess. The weakness is a typical authentication bypass (CWE-288) which compromises the confidentiality and integrity of user sessions and potentially any data accessed thereafter.

Affected Systems

All Drupal Internationalization Single Sign-On installations from version 0.0.0 up to and including 1.8.0 are affected. The vulnerability exists in the module’s handling of alternate sign‑on paths.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable; the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an alternate authentication URL that an attacker can construct and use to obtain a valid session. The exploitation requires only access to the application’s domain and knowledge of the module’s URL structure. The severity is potentially high due to the complete bypass of authentication controls.

Generated by OpenCVE AI on August 26, 2026 at 00:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Drupal Internationalization Single Sign-On module to the latest patch or a version newer than 1.8.0.
  • If the module is not required for site operation, disable or uninstall it until a fix is applied.
  • Audit SSO configurations and user accounts to ensure that only authorized users can access authenticated services and monitor for suspicious login patterns.

Generated by OpenCVE AI on August 26, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
Title Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081
Weaknesses CWE-288
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-08-25T22:22:12.799Z

Reserved: 2026-07-22T17:06:41.738Z

Link: CVE-2026-16639

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T23:16:56.673

Modified: 2026-08-25T23:16:56.673

Link: CVE-2026-16639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T00:45:03Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel