Remote Code Execution Vulnerability in Drupal's Mother May I Plugin
CVE-2026-11913

9.8CRITICAL

Key Information:

Vendor

Drupal

Vendor
CVE Published:
10 July 2026

What is CVE-2026-11913?

A remote code execution vulnerability exists in the Mother May I plugin for Drupal, exposing affected versions to potential exploitation. Attackers could leverage this flaw to execute arbitrary code on the server, which could lead to unauthorized access and system compromise. It's crucial for users and administrators to patch their installations promptly to mitigate this risk.

Affected Version(s)

Mother May I *.*

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.