Missing Authorization Vulnerability in Drupal Core from Drupal
CVE-2026-15916

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
25 August 2026

What is CVE-2026-15916?

A missing authorization flaw in Drupal core enables attackers to bypass restrictions, resulting in forceful browsing across affected versions. This vulnerability permits unauthorized access to content or user data, which can lead to privacy breaches and potential misuse of sensitive information.

Affected Version(s)

Drupal core 0.0.0 < 10.6.13

Drupal core 11.3.0 < 11.3.14

Drupal core 11.4.0 < 11.4.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offensive-ai
Benji Fisher (benjifisher)
Kim Pepper (kim.pepper)
Mohit Aghera (mohit_aghera)
Benji Fisher (benjifisher)
catch (catch)
Lee Rowlands (larowlan)
Juraj Nemec (poker10)
Jess (xjm)
.