Description
Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Access Bypass via Forceful Browsing
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an incorrect authorization flaw in the Drupal Quick Tabs module that allows an attacker to perform forceful browsing. By requesting URLs that should be protected, an unauthenticated or insufficiently privileged user can view tab content that should be restricted. This creates a confidentiality risk in which sensitive information accessible only to certain roles may be exposed to all users. The issue is classified as moderately critical in the advisories, reflecting the possibility of widespread access if the module is widely deployed.

Affected Systems

Drupal sites that have the Quick Tabs module installed, specifically any deployed version from 0.0.0 through 4.3.1. Administrators should review the modules and version numbers in use and compare them to this affected range.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity; no EPSS value is available, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be a direct HTTP request to a Quick Tabs URL that bypasses normal authorization checks. Because the flaw stems from an incorrect permission check, an attacker who can craft or guess the tab endpoint can gain unauthorized read access. The impact is limited to data exposure rather than code execution or system compromise, yet it can be significant if sensitive tab data is involved. The lack of publicly reported exploitation does not eliminate risk; deployment of the module remains a potential attack surface until the flaw is corrected.

Generated by OpenCVE AI on September 3, 2026 at 10:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drupal Quick Tabs to the newest release that contains the authorization fix (any version newer than 4.3.1).
  • If an immediate update is not possible, restrict access to Quick Tabs URLs by configuring Drupal permissions or placing firewall rules that deny requests to these paths unless the user has explicit privileges.
  • Audit the site’s permissions structure to ensure that roles are assigned appropriate rights and that no role has unintended access to tab content.

Generated by OpenCVE AI on September 3, 2026 at 10:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Quick Tabs Project
Quick Tabs Project quick Tabs
CPEs cpe:2.3:a:quick_tabs_project:quick_tabs:*:*:*:*:*:drupal:*:*
Vendors & Products Quick Tabs Project
Quick Tabs Project quick Tabs

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal quick Tabs
Vendors & Products Drupal
Drupal quick Tabs

Wed, 02 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.
Title Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099
Weaknesses CWE-863
References

Subscriptions

Drupal Quick Tabs
Quick Tabs Project Quick Tabs
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T18:39:32.239Z

Reserved: 2026-08-12T17:21:18.777Z

Link: CVE-2026-73477

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T13:18:08.530

Modified: 2026-09-16T15:35:32.647

Link: CVE-2026-73477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:15:05Z

Weaknesses