Modification of Assumed-Immutable Data Vulnerability in Drupal Translate by GTranslate
CVE-2026-8492
2.7LOW
What is CVE-2026-8492?
A Modification of Assumed-Immutable Data (MAID) vulnerability exists in the Translate module of Drupal when used alongside GTranslate, potentially allowing an attacker to spoof resource locations. This poses significant risks to the integrity of content served through the application. Users on versions prior to 3.0.5 are advised to upgrade to mitigate threats associated with this vulnerability.
Affected Version(s)
Translate Drupal with GTranslate 0.0.0 < 3.0.5
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pierre Rudloff (prudloff)
Edvard Ananyan (edo888)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
