Cross-Site Scripting Vulnerability in Drupal Core from Acquia
CVE-2026-15917

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
25 August 2026

What is CVE-2026-15917?

A vulnerability in Drupal core enables attackers to execute malicious scripts in the context of a user's session, leading to potential data leakage and session hijacking. This Cross-Site Scripting (XSS) vulnerability affects specific versions of Drupal core, specifically from 11.3.0 to 11.3.14 and others, exposing web applications built on this platform to significant security risks. Proper input validation and filtering mechanisms are crucial to mitigate these threats, and users are advised to upgrade to the latest versions to ensure robust security.

Affected Version(s)

Drupal core 11.3.0 < 11.3.14

Drupal core 11.4.0 < 11.4.4

Drupal core 0.0.0 < 11.2.*

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Rudloff (prudloff)
Shawn Duncan (fathershawn)
Pierre Rudloff (prudloff)
catch (catch)
Lee Rowlands (larowlan)
Dave Long (longwave)
Jess (xjm)
.