Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpublished Node Permissions: from 0.0.0 before 1.7.0.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2026-029 |
|
History
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal
Drupal unpublished Node Permissions |
|
| Vendors & Products |
Drupal
Drupal unpublished Node Permissions |
Thu, 26 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpublished Node Permissions: from 0.0.0 before 1.7.0. | |
| Title | Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-029 | |
| Weaknesses | CWE-863 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2026-03-26T20:10:26.886Z
Reserved: 2026-03-26T19:50:20.404Z
Link: CVE-2026-4933
No data.
Status : Received
Published: 2026-03-26T21:17:10.360
Modified: 2026-03-26T21:17:10.360
Link: CVE-2026-4933
No data.
OpenCVE Enrichment
Updated: 2026-03-27T08:32:08Z
Weaknesses