Description
Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.
Published: 2026-08-25
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential confidentiality, integrity, or availability compromise, but exact impact is unspecified
Action: Disable Module
AI Analysis

Impact

The advisory identifies a vulnerability in the Drupal Powerful Surveys contributed module. The official description does not specify the nature, mechanism, or exact consequences of the flaw. As a result, the precise impact—whether it could lead to data exposure, arbitrary code execution, or denial of service—remains unknown.

Affected Systems

All installations of the Drupal Powerful Surveys module are affected. The advisory lists the affected versions as '*.*', indicating that every released build of the module could be vulnerable. The module is part of the Drupal ecosystem and is typically deployed via web interfaces exposed to external users.

Risk and Exploitability

The CVSS score is 5.7. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Because the module is unsupported, no official patch exists. The risk remains moderate, especially if the module is exposed to web traffic. The likely attack vector, inferred from typical Drupal module architecture, involves sending crafted requests to the module’s endpoints. Without a fix, attackers could potentially exploit the flaw remotely, though the exact conditions for exploitation are unclear.

Generated by OpenCVE AI on August 26, 2026 at 21:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Uninstall or disable the Powerful Surveys module to eliminate the vulnerability
  • If a security fix becomes available, upgrade the module immediately
  • Regularly monitor Drupal security advisories and keep all contributed modules at the latest secure releases to prevent new vulnerabilities

Generated by OpenCVE AI on August 26, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal powerful Surveys
Vendors & Products Drupal
Drupal powerful Surveys

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-94

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.
Title Powerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092
References

Subscriptions

Drupal Powerful Surveys
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-08-26T18:53:24.106Z

Reserved: 2026-07-29T16:42:38.736Z

Link: CVE-2026-18261

cve-icon Vulnrichment

Updated: 2026-08-26T18:53:21.100Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-25T23:16:57.810

Modified: 2026-08-28T15:29:44.967

Link: CVE-2026-18261

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:34:16Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')