Access Control Bypass in Drupal 7 Internationalization Module
CVE-2026-0748
What is CVE-2026-0748?
The i18n_node submodule in the Drupal 7 Internationalization module presents a security flaw that enables users with the 'Translate content' and 'Administer content translations' permissions to access unpublished nodes. This vulnerability allows unauthorized users to view unpublished node titles and IDs through the translation UI and its autocomplete widget, circumventing the intended access controls. It is crucial for organizations using affected versions to address this weakness to ensure sensitive content remains protected.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Internationalization (i18n) - i18n_node submodule 7.x-1.0 <= 7.x-1.35
