Description
Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is reported for the Drupal PanKM module, but the official description provides no detail about the weakness or attacker capabilities. The module is listed as Critical and Unsupported, indicating that this issue was never maintained beyond a certain date. Because the advisory lacks a specific attack path, the exact impact—such as remote code execution, privilege escalation, or data disclosure—cannot be determined from the information provided.

Affected Systems

Drupal installations that include the PanKM module are affected. All documented versions are considered impacted, but no further version granularity is provided.

Risk and Exploitability

No CVSS, EPSS, or KEV data are available. The EPSS score is not provided, and the KEV flag indicates that this vulnerability is not listed in the CISA KEV catalog. The vendor’s classification as Critical and Unsupported implies a severe potential impact, but no official patch or workaround is documented. Until a fix is released, the risk remains uncertain but could be significant for systems still running the PanKM module.

Generated by OpenCVE AI on August 26, 2026 at 02:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or uninstall the PanKM module immediately to eliminate the vulnerability.
  • Monitor the Drupal security advisory page for any patch or update related to PanKM SA-CONTRIB-2026-083.
  • Once an official patch is released, upgrade the PanKM module to the fixed version or permanently remove it if vendor support is discontinued.

Generated by OpenCVE AI on August 26, 2026 at 02:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-732

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
Title PanKM - Critical - Unsupported - SA-CONTRIB-2026-083
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-08-25T22:22:05.938Z

Reserved: 2026-07-22T17:06:47.500Z

Link: CVE-2026-16646

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T23:16:57.423

Modified: 2026-08-25T23:16:57.423

Link: CVE-2026-16646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T02:15:16Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-732

    Incorrect Permission Assignment for Critical Resource