Description
Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via forceful browsing
Action: Patch
AI Analysis

Impact

A missing authorization check in the Drupal Data field module lets attackers forcefully browse URLs and retrieve sensitive data. The flaw is an example of inadequate access control, allowing any user to view content they should not be able to. The resulting exposure can compromise confidentiality of information stored in data fields.

Affected Systems

The vulnerability affects the Drupal Data field module in the Drupal platform. Versions from 0.0.0 up to and including 2.0.13 are affected. Administrators should verify the module version they run and consider upgrading to a fixed release.

Risk and Exploitability

Because no EPSS score is available, the likelihood of exploitation is not quantified, and the issue is not listed in the CISA KEV catalog, it is considered a lower‑profile risk. However, as the flaw permits forced browsing of arbitrary data field pages, it is exploitable via a web request from any authenticated or unauthenticated user, assuming the target site exposes the module’s endpoints. The CVSS score of 5.3 indicates a moderate severity level. It remains a significant concern for sites that expose sensitive data through the Data field module.

Generated by OpenCVE AI on September 3, 2026 at 10:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Drupal Data field module to a version newer than 2.0.13, ensuring the fix for the missing authorization check is applied.
  • If an upgrade is not yet available, temporarily disable the Data field module and remove any exposed URLs that could be forcefully accessed.
  • Implement strict role‑based access controls to limit which users can view data field content, mitigating the risk until the module is patched.

Generated by OpenCVE AI on September 3, 2026 at 10:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Data Field Project
Data Field Project data Field
CPEs cpe:2.3:a:data_field_project:data_field:*:*:*:*:*:drupal:*:*
Vendors & Products Data Field Project
Data Field Project data Field

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal data Field
Vendors & Products Drupal
Drupal data Field

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
References

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.
Title Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108
Weaknesses CWE-862
References

Subscriptions

Data Field Project Data Field
Drupal Data Field
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T19:01:56.277Z

Reserved: 2026-08-26T17:16:29.879Z

Link: CVE-2026-81269

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T13:18:12.917

Modified: 2026-09-09T18:37:12.863

Link: CVE-2026-81269

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:45:05Z

Weaknesses