Description
Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.
Published: 2026-09-02
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in the Drupal Data field module lets attackers forcefully browse URLs and retrieve sensitive data. The flaw is an example of inadequate access control, allowing any user to view content they should not be able to. The resulting exposure can compromise confidentiality of information stored in data fields.

Affected Systems

The vulnerability affects the Drupal Data field module in the Drupal platform. Versions from 0.0.0 up to and including 2.0.13 are affected. Administrators should verify the module version they run and consider upgrading to a fixed release.

Risk and Exploitability

Because no EPSS score is available, the likelihood of exploitation is not quantified, and the issue is not listed in the CISA KEV catalog, it is considered a lower‑profile risk. However, as the flaw permits forced browsing of arbitrary data field pages, it is exploitable via a web request from any authenticated or unauthenticated user, assuming the target site exposes the module’s endpoints. The absence of a CVSS assignment in the data makes it unclear how severe the impact is scored. It remains a significant concern for sites that expose sensitive data through the Data field module.

Generated by OpenCVE AI on September 2, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Drupal Data field module to a version newer than 2.0.13, ensuring the fix for the missing authorization check is applied.
  • If an upgrade is not yet available, temporarily disable the Data field module and remove any exposed URLs that could be forcefully accessed.
  • Implement strict role‑based access controls to limit which users can view data field content, mitigating the risk until the module is patched.

Generated by OpenCVE AI on September 2, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.
Title Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108
Weaknesses CWE-862
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T13:13:26.506Z

Reserved: 2026-08-26T17:16:29.879Z

Link: CVE-2026-81269

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T13:18:12.917

Modified: 2026-09-02T13:53:45.597

Link: CVE-2026-81269

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:30:05Z

Weaknesses