๐Ÿ” CVE Alert

CVE-2026-15916

UNKNOWN 0.0

Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.

CWE CWE-862
Vendor drupal
Product drupal core
Ecosystems
Industries
WebMedia
Published Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for drupal drupal core

Be the first to know when new unknown vulnerabilities affecting drupal drupal core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Drupal / Drupal core
0.0.0 < 10.6.13 11.3.0 < 11.3.14 11.4.0 < 11.4.4 0.0.0 < 11.0.* 0.0.0 < 11.1.* 0.0.0 < 11.2.*

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
drupal.org: https://www.drupal.org/sa-core-2026-010

Credits

offensive-ai Benji Fisher (benjifisher) Kim Pepper (kim.pepper) Mohit Aghera (mohit_aghera) Benji Fisher (benjifisher) catch (catch) Lee Rowlands (larowlan) Juraj Nemec (poker10) Jess (xjm)