Description
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
Published: 2026-07-10
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing Authorization in Drupal FlowDrop enables forceful browsing of pages that should be protected by authentication or authorization attacker with web access to the FlowDrop instance to request URLs that are normally restricted, potentially exposing sensitive data or user information. The CVSS score of 5.4 signifies a moderate severity, indicating that the missing authorization check represents a significant compromise of confidentiality and integrity.

Affected Systems

Drupal FlowDrop versions from 0.0.0 through 1.6.0 are affected. Any installation within this range without additional access controls would be vulnerable.

Risk and Exploitability

Attackers would need to send HTTP requests to restricted routes that normally require authentication or authorization. The EPSS score indicates less than a 1% probability of exploitation at this time. Because the vulnerability permits unauthorized access to protected resources, exploitation could lead to privacy and integrity risks. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploitation of this issue.

Generated by OpenCVE AI on July 29, 2026 at 09:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drupal FlowDrop to the latest version that addresses the missing authorization check.
  • If an upgrade is not immediately possible, block or restrict direct web access to FlowDrop resources using firewall or web-server ACLs to prevent forceful application-level access controls, ensuring that all protected routes enforce proper authentication and authorization as described in CWE-862.
  • Configure Drupal role ensuringprivileged protected routes.

Generated by OpenCVE AI on July 29, 2026 at 09:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal flowdrop
Vendors & Products Drupal
Drupal flowdrop

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
Title FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T17:47:17.164Z

Reserved: 2026-07-01T17:08:05.253Z

Link: CVE-2026-58589

cve-icon Vulnrichment

Updated: 2026-07-13T17:32:03.641Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:45:04Z

Weaknesses