Description
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Theme Negotiation by Rules allows Cross Site Request Forgery.This issue affects Theme Negotiation by Rules: from 0.0.0 before 1.2.1.
Published: 2026-03-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery
Action: Apply Patch
AI Analysis

Impact

Theme Negotiation by Rules contains a Cross‑Site Request Forgery weakness that lets an attacker craft requests that are executed by a logged‑in user’s browser. Because the module does not validate the origin of submitted forms, a malicious site can trigger privileged actions on the Drupal site, such as changing theme settings or other configuration data. This flaw is classified as CWE‑352.

Affected Systems

The vulnerability is present in Drupal installations that use the contributed module Theme Negotiation by Rules. All releases from version 0.0.0 up to, but not including, 1.2.1 are affected. The issue does not involve core Drupal code.

Risk and Exploitability

The advisory assigns a CVSS score of 4.3, indicating moderate severity, and an EPSS score of less than 1%, implying a low current exploitation probability. This flaw is not listed in the CISA KEV catalog, so no active weaponized attacks are reported. An attacker would need to entice a legitimate user to load a malicious page that submits a forged request, a common CSRF scenario. Consequently, any site that uses the affected module should treat the risk as moderate and address it promptly.

Generated by OpenCVE AI on April 1, 2026 at 05:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Theme Negotiation by Rules module to version 1.2.1 or later, which removes the CSRF flaw.
  • Ensure that all forms on the site include the required CSRF tokens and that Drupal’s built‑in CSRF protections are enabled.
  • Audit user activity for unexpected state‑changing requests that may indicate a CSRF attack.
  • If the module cannot be updated immediately, disable it or restrict its access to trusted administrators until a patch is applied.

Generated by OpenCVE AI on April 1, 2026 at 05:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Webikon
Webikon theme Negotiation By Rules
CPEs cpe:2.3:a:webikon:theme_negotiation_by_rules:*:*:*:*:*:drupal:*:*
Vendors & Products Webikon
Webikon theme Negotiation By Rules

Thu, 26 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Thu, 26 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal theme Negotiation By Rules
Vendors & Products Drupal
Drupal theme Negotiation By Rules

Wed, 25 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Drupal Theme Negotiation by Rules allows Cross Site Request Forgery.This issue affects Theme Negotiation by Rules: from 0.0.0 before 1.2.1.
Title Theme Negotiation by Rules - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-012
Weaknesses CWE-352
References

Subscriptions

Drupal Theme Negotiation By Rules
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-03-26T14:36:19.903Z

Reserved: 2026-02-25T16:59:25.803Z

Link: CVE-2026-3211

cve-icon Vulnrichment

Updated: 2026-03-25T20:02:11.416Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-25T16:16:22.080

Modified: 2026-03-31T19:23:14.010

Link: CVE-2026-3211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T07:59:13Z

Weaknesses