Cross-site Scripting Vulnerability in Drupal Entity Browser Affecting Specific Versions
CVE-2026-18986

4.8MEDIUM

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-18986?

A Cross-site Scripting (XSS) vulnerability has been identified in the Drupal Entity Browser, allowing attackers to inject malicious scripts. This security flaw affects versions from 0.0.0 to 2.16.0, potentially compromising user interactions by enabling stored XSS attacks. It is crucial for users of affected versions to apply security updates promptly to protect against exploitation.

Affected Version(s)

Entity Browser 0.0.0 < 2.16.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Rudloff (prudloff)
Julian Pustkuchen (anybody)
Sascha Grossenbacher (berdir)
Pierre Rudloff (prudloff)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Pierre Rudloff (prudloff)
.