Description
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
Published: 2026-09-02
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The Drupal Content Moderation Notifications module contains a privilege defined with unsafe actions vulnerability that allows users to execute operations normally restricted to higher‑level roles. This flaw can enable an attacker to modify content, bypass moderation routes, or otherwise alter site behavior without proper authorization. The weakness is identified as CWE‑267, indicating improper privilege management.

Affected Systems

Drupal sites using the Content Moderation Notifications contributed module versions from 0.0.0 through 3.9.0 are affected. Any installation that has not yet upgraded past 3.9.0 remains vulnerable and may be at risk if the module is actively used on the site.

Risk and Exploitability

The CVSS score is 3.3, indicating a low severity, and no EPSS score is available. The vulnerability is not listed in CISA KEV. Privilege escalation is possible if an attacker can trigger the module’s unsafe actions through the web interface. The typical attack vector is through a compromised or unauthenticated user session interacting with the module, but this is inferred from the described vulnerability. Because the severity is low and exploitation is dependent on the site's role configuration, the overall risk should be evaluated in context but is not automatically high.

Generated by OpenCVE AI on September 3, 2026 at 11:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Content Moderation Notifications module to the latest version released after 3.9.0 that contains the fix.
  • Review Drupal role permissions to ensure that users only have access to the actions their role requires, eliminating unnecessary elevated rights.
  • Validate that site configuration does not grant admin or content moderation privileges to untrusted users, and follow Drupal’s security best practices for role management.

Generated by OpenCVE AI on September 3, 2026 at 11:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal content Moderation Notifications
Vendors & Products Drupal
Drupal content Moderation Notifications

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
Title Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107
Weaknesses CWE-267
References

Subscriptions

Drupal Content Moderation Notifications
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T19:01:16.122Z

Reserved: 2026-08-26T16:19:43.744Z

Link: CVE-2026-81161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T13:18:11.887

Modified: 2026-09-02T19:18:05.483

Link: CVE-2026-81161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T11:45:03Z

Weaknesses
  • CWE-267

    Privilege Defined With Unsafe Actions