Privilege Escalation Vulnerability in Drupal OpenID Connect / OAuth Client
CVE-2026-3532

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
26 March 2026

What is CVE-2026-3532?

A vulnerability in the Drupal OpenID Connect / OAuth client relates to improper handling of case sensitivity, which can lead to privilege escalation. When users interact with the authentication mechanism, the oversight allows for unauthorized access under certain conditions. This issue affects versions from 0.0.0 prior to 1.5.0, making it crucial for users to upgrade to secure their systems effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

OpenID Connect / OAuth client 0.0.0 < 1.5.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eric Smith (ericgsmith)
Philip Frilling (pfrilling)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Juraj Nemec (poker10)
.