Description
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
Published: 2026-07-10
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Drupal FlowDrop suffers from a Missing Authorization flaw, allowing attackers to forcefully browse URLs and retrieve content that should be protected. This weakness could expose confidential data or allow modification of content without proper permissions, undermining the integrity of the site and potentially granting control over site functions. The severity is moderate, as the exploit requires no special privileges other than the ability to send HTTP requests, but it can significantly broaden an attacker’s view of the system. This Missing Authorization flaw862.

Affected Systems

All installations of the Drupal FlowDrop component from version 0.0.0 up to and including 1.6.0 are vulnerable. This includes any web sites that have deployed these versions without later updates.

Risk and Exploitability

The vulnerability is exploitable via standard web requests; an attacker may craft URLs to access restricted pages or resources. Because the EPSS score is less than 1% and the issue is not listed in CISA KEV, there is no publicly known exploit code, but the underlying missing authorization plainly permits unauthorized browsing. The risk remains moderate to high given the potential for significant data exposure or unauthorized configuration changes.

Generated by OpenCVE AI on July 23, 2026 at 06:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Drupal FlowDrop to a released version newer than 1.6.0 or apply the official patch provided by the Drupal security team.
  • If a patch is not immediately available, disable or remove the FlowDrop module from any sites that do not require its functionality until an update is applied.
  • Ensure that after the update all access controls are correctly configured, audit permissions for content types exposed by FlowDrop, and monitor logs for anomalous access patterns.

Generated by OpenCVE AI on July 23, 2026 at 06:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal flowdrop
Vendors & Products Drupal
Drupal flowdrop

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
Title FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T17:48:20.835Z

Reserved: 2026-07-01T17:08:05.253Z

Link: CVE-2026-58590

cve-icon Vulnrichment

Updated: 2026-07-13T17:33:01.193Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T07:00:05Z

Weaknesses