Description
Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
Published: 2026-08-25
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Assess Impact
AI Analysis

Impact

The vulnerability is reported for the Drupal PanKM module, but the official description provides no detail about the weakness or attacker capabilities. The module is listed as Critical and Unsupported, indicating that this issue was never maintained beyond a certain date. Because the advisory lacks a specific attack path, the exact impact—such as remote code execution, privilege escalation, or data disclosure—cannot be determined from the information provided.

Affected Systems

Drupal installations that include the PanKM module are affected. All documented versions are considered impacted, but no further version granularity is provided.

Risk and Exploitability

The CVSS score is 5.7, EPSS is <1%, KEV not listed. The vulnerability is a weakness in authentication (CWE‑306) that could allow a remote attacker to craft HTTP requests to the PanKM module, bypass authentication checks and gain unauthorized access to restricted functions or data. Though the advisory does not record any publicly known exploits, the critical classification and authentication bypass nature warrant continuous monitoring; the issue is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 26, 2026 at 21:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or uninstall the PanKM module immediately to eliminate the vulnerability.
  • Monitor the Drupal security advisory page for any patch or update related to PanKM SA-CONTRIB-2026-083.
  • Once an official patch is released, upgrade the PanKM module to the fixed version or permanently remove it if vendor support is discontinued.

Generated by OpenCVE AI on August 26, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 26 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-732

Wed, 26 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-732

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
Title PanKM - Critical - Unsupported - SA-CONTRIB-2026-083
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-08-26T14:49:58.454Z

Reserved: 2026-07-22T17:06:47.500Z

Link: CVE-2026-16646

cve-icon Vulnrichment

Updated: 2026-08-26T14:48:59.821Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-25T23:16:57.423

Modified: 2026-08-28T15:29:44.967

Link: CVE-2026-16646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:30:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function