Description
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
Published: 2026-09-02
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Drupal Content Moderation Notifications module contains a privilege defined with unsafe actions vulnerability that allows users to execute operations normally restricted to higher-level roles. This flaw can enable an attacker to modify content, bypass moderation routes, or otherwise alter site behavior without proper authorization. The weakness is identified as CWE‑267, indicating improper privilege management.

Affected Systems

Drupal sites using the Content Moderation Notifications contributed module versions from 0.0.0 through 3.9.0 are affected. Any installation that has not yet upgraded past 3.9.0 remains vulnerable and may be at risk if the module is actively used on the site.

Risk and Exploitability

CVSS and EPSS scores are not published, and the vulnerability is not listed in the CISA KEV catalog, but the ability to elevate privileges presents significant risk to confidentiality and integrity. Exploitation requires interaction with the module’s unsafe actions, typically through the normal web interface, meaning that attackers with access to a user session or unauthenticated interactions can trigger the flaw. Given the direct privilege escalation impact, the risk level is high and should be mitigated promptly.

Generated by OpenCVE AI on September 2, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Content Moderation Notifications module to the latest version released after 3.9.0 that contains the fix.
  • Review Drupal role permissions to ensure that users only have access to the actions their role requires, eliminating unnecessary elevated rights.
  • Validate that site configuration does not grant admin or content moderation privileges to untrusted users, and follow Drupal’s security best practices for role management.

Generated by OpenCVE AI on September 2, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
Title Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107
Weaknesses CWE-267
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T12:32:03.335Z

Reserved: 2026-08-26T16:19:43.744Z

Link: CVE-2026-81161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T13:18:11.887

Modified: 2026-09-02T13:53:45.597

Link: CVE-2026-81161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:30:05Z

Weaknesses
  • CWE-267

    Privilege Defined With Unsafe Actions