Description
Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect authorization rule in the Drupal Diff module permits forceful browsing, allowing attackers to bypass permissions and access content that should be restricted. This weakness, identified as CWE-863, means that anyone can read protected Diff entries without authenticating or possessing elevated rights.

Affected Systems

Drupal sites employing the Diff module versions 0.0.0 through 2.0.1 or 2.1.0 through 2.1.1 are impacted. The issue applies to any deployment of these releases, regardless of other site configuration.

Risk and Exploitability

The vulnerability can be exploited remotely via an HTTP request to the Diff module endpoints. Based on the description, it is inferred that the likely attack vector is a standard web request and that no special privileges are required for exploitation. The CVSS score of 5.3 indicates a moderate severity level. EPSS data is unavailable, and the flaw is not listed in CISA KEV. Given its access‑bypass nature, the flaw could allow unprivileged users to retrieve confidential content.

Generated by OpenCVE AI on September 3, 2026 at 11:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest version of the Diff module that contains the fix, preferably a release newer than 2.1.1.
  • Restrict access to Diff URLs by configuring Drupal’s path access restrictions so that only authenticated administrators or designated roles can view them.
  • Adjust Drupal permissions so that only appropriate user roles have the view diff content permission, and audit logs for unauthorized access attempts.

Generated by OpenCVE AI on September 3, 2026 at 11:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 03 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal diff
Vendors & Products Drupal
Drupal diff

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 02 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.
Title Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T18:36:03.058Z

Reserved: 2026-08-12T17:21:18.777Z

Link: CVE-2026-73478

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T13:18:08.637

Modified: 2026-09-02T19:18:02.607

Link: CVE-2026-73478

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T11:45:03Z

Weaknesses