Impact
The vulnerability is reported for the Drupal PanKM module, but the official description provides no detail about the weakness or attacker capabilities. The module is listed as Critical and Unsupported, indicating that this issue was never maintained beyond a certain date. Because the advisory lacks a specific attack path, the exact impact—such as remote code execution, privilege escalation, or data disclosure—cannot be determined from the information provided.
Affected Systems
Drupal installations that include the PanKM module are affected. All documented versions are considered impacted, but no further version granularity is provided.
Risk and Exploitability
The CVSS score is 5.7, EPSS is <1%, KEV not listed. The vulnerability is a weakness in authentication (CWE‑306) that could allow a remote attacker to craft HTTP requests to the PanKM module, bypass authentication checks and gain unauthorized access to restricted functions or data. Though the advisory does not record any publicly known exploits, the critical classification and authentication bypass nature warrant continuous monitoring; the issue is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment