Missing Authorization Vulnerability in Drupal Data Field
CVE-2026-81269

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81269?

A missing authorization vulnerability exists in the Data Field of Drupal, allowing unauthorized users to perform forceful browsing. This flaw enables users to access restricted content without proper permissions. The affected versions range from 0.0.0 to 2.0.13, emphasizing the need for timely updates to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Data field 0.0.0 < 2.0.13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcus Johansson (marcus_johansson)
Drew Webber (mcdruid)
Steven Jones (steven jones)
Joseph Olstad (joseph.olstad)
NGUYEN Bao (lazzyvn)
Marcus Johansson (marcus_johansson)
Steven Jones (steven jones)
Swan Kalata (akalata)
David Stoline (dstol)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Juraj Nemec (poker10)
Jess (xjm)
.