Authorization Flaw in Drupal Diff Affects Multiple Versions
CVE-2026-73478

Currently unrated

Key Information:

Vendor

Drupal

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-73478?

An authorization flaw in the Drupal Diff module enables Forceful Browsing, potentially allowing unauthorized users to access restricted resources. This vulnerability impacts specific versions of Diff, underscoring the importance of maintaining updated system components to safeguard against unauthorized access and data exposure.

Affected Version(s)

Diff 0.0.0 < 2.0.1

Diff 2.1.0 < 2.1.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexei Rayu (alexrayu)
Adam Bramley (acbramley)
Derek Wright (dww)
Lee Rowlands (larowlan)
Swan Kalata (akalata)
Greg Knaddison (greggles)
Lee Rowlands (larowlan)
.