Incorrect Authorization Vulnerability in Drupal Edit In-Place Field
CVE-2026-18985
8.1HIGH
What is CVE-2026-18985?
An incorrect authorization vulnerability exists in the Drupal Edit In-Place Field module, allowing unauthorized users to perform forceful browsing. This weakness affects versions from 0.0.0 to 2.1.1, potentially exposing sensitive data or functionality to users without proper permissions. It highlights the critical need for developers and website administrators to ensure that proper access controls are implemented and maintained.
Affected Version(s)
Edit in-place field 0.0.0 < 2.1.1
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Drew Webber (mcdruid)
Bálint Nagy (nagy.balint)
Neil Drumm (drumm)
Greg Knaddison (greggles)
