Impact
The Drupal Content Moderation Notifications module contains a privilege defined with unsafe actions vulnerability that allows users to execute operations normally restricted to higher-level roles. This flaw can enable an attacker to modify content, bypass moderation routes, or otherwise alter site behavior without proper authorization. The weakness is identified as CWE‑267, indicating improper privilege management.
Affected Systems
Drupal sites using the Content Moderation Notifications contributed module versions from 0.0.0 through 3.9.0 are affected. Any installation that has not yet upgraded past 3.9.0 remains vulnerable and may be at risk if the module is actively used on the site.
Risk and Exploitability
CVSS and EPSS scores are not published, and the vulnerability is not listed in the CISA KEV catalog, but the ability to elevate privileges presents significant risk to confidentiality and integrity. Exploitation requires interaction with the module’s unsafe actions, typically through the normal web interface, meaning that attackers with access to a user session or unauthenticated interactions can trigger the flaw. Given the direct privilege escalation impact, the risk level is high and should be mitigated promptly.
OpenCVE Enrichment