Authorization Flaw in Drupal Quick Tabs Plugin
CVE-2026-73477

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-73477?

An authorization flaw in the Drupal Quick Tabs plugin enables attackers to exploit forceful browsing. This vulnerability allows unauthorized users to access restricted areas of the site, potentially leading to data exposure or manipulation. Quick Tabs versions ranging from 0.0.0 to 4.3.1 are affected, making it essential for users to update and apply security patches to protect their web applications.

Affected Version(s)

Quick Tabs 0.0.0 < 4.3.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joël Pittet (joelpittet)
Joël Pittet (joelpittet)
Swan Kalata (akalata)
Neil Drumm (drumm)
Greg Knaddison (greggles)
.