Access Control Bypass in Drupal 7 Internationalization Module
CVE-2026-0748
5.3MEDIUM
What is CVE-2026-0748?
The i18n_node submodule in the Drupal 7 Internationalization module presents a security flaw that enables users with the 'Translate content' and 'Administer content translations' permissions to access unpublished nodes. This vulnerability allows unauthorized users to view unpublished node titles and IDs through the translation UI and its autocomplete widget, circumventing the intended access controls. It is crucial for organizations using affected versions to address this weakness to ensure sensitive content remains protected.
Affected Version(s)
Internationalization (i18n) - i18n_node submodule 7.x-1.0 <= 7.x-1.35
