Missing Authorization in Drupal Facets Allows Forceful Browsing
CVE-2025-9549

Currently unrated

Key Information:

Vendor

Drupal

Status
Vendor
CVE Published:
10 October 2025

What is CVE-2025-9549?

A missing authorization vulnerability exists in the Drupal Facets module, which can lead to forceful browsing. This vulnerability primarily affects versions prior to 2.0.10 and 3.0.1, allowing unauthorized users to access restricted content. Malicious actors could exploit this flaw to manipulate user sessions and gain access to sensitive information, posing a significant threat to data security.

Affected Version(s)

Facets 0.0.0 < 2.0.10

Facets 3.0.0 < 3.0.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Damien McKenna (damienmckenna)
Benji Fisher (benjifisher)
Joris Vercammen (borisson_)
Damien McKenna (damienmckenna)
Thomas Seidl (drunken monkey)
Jimmy Henderickx (strykaizer)
Benji Fisher (benjifisher)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Cathy Theys (yesct)
.
CVE-2025-9549 : Missing Authorization in Drupal Facets Allows Forceful Browsing