Impact
The Drupal Content Moderation Notifications module contains a privilege defined with unsafe actions vulnerability that allows users to execute operations normally restricted to higher‑level roles. This flaw can enable an attacker to modify content, bypass moderation routes, or otherwise alter site behavior without proper authorization. The weakness is identified as CWE‑267, indicating improper privilege management.
Affected Systems
Drupal sites using the Content Moderation Notifications contributed module versions from 0.0.0 through 3.9.0 are affected. Any installation that has not yet upgraded past 3.9.0 remains vulnerable and may be at risk if the module is actively used on the site.
Risk and Exploitability
The CVSS score is 3.3, indicating a low severity, and no EPSS score is available. The vulnerability is not listed in CISA KEV. Privilege escalation is possible if an attacker can trigger the module’s unsafe actions through the web interface. The typical attack vector is through a compromised or unauthenticated user session interacting with the module, but this is inferred from the described vulnerability. Because the severity is low and exploitation is dependent on the site's role configuration, the overall risk should be evaluated in context but is not automatically high.
OpenCVE Enrichment