Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated): from 0.0.0 before 1.2.0.
Subscriptions
No data.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2026-020 |
|
History
Thu, 26 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated): from 0.0.0 before 1.2.0. | |
| Title | File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-020 | |
| Weaknesses | CWE-863 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2026-03-26T20:02:25.154Z
Reserved: 2026-03-04T16:41:52.841Z
Link: CVE-2026-3525
No data.
Status : Received
Published: 2026-03-26T21:17:08.437
Modified: 2026-03-26T21:17:08.437
Link: CVE-2026-3525
No data.
OpenCVE Enrichment
No data.
Weaknesses