Incorrect Authorization Vulnerability in Drupal Edit In-Place Field
CVE-2026-18985

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
25 August 2026

What is CVE-2026-18985?

An incorrect authorization vulnerability exists in the Drupal Edit In-Place Field module, allowing unauthorized users to perform forceful browsing. This weakness affects versions from 0.0.0 to 2.1.1, potentially exposing sensitive data or functionality to users without proper permissions. It highlights the critical need for developers and website administrators to ensure that proper access controls are implemented and maintained.

Affected Version(s)

Edit in-place field 0.0.0 < 2.1.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Drew Webber (mcdruid)
Bálint Nagy (nagy.balint)
Neil Drumm (drumm)
Greg Knaddison (greggles)
.