CVE-2026-15916
Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
| CWE | CWE-862 |
| Vendor | drupal |
| Product | drupal core |
| Ecosystems | |
| Industries | WebMedia |
| Published | Aug 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for drupal drupal core
Be the first to know when new unknown vulnerabilities affecting drupal drupal core are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Drupal / Drupal core
0.0.0 < 10.6.13 11.3.0 < 11.3.14 11.4.0 < 11.4.4 0.0.0 < 11.0.* 0.0.0 < 11.1.* 0.0.0 < 11.2.*
Credits
offensive-ai Benji Fisher (benjifisher) Kim Pepper (kim.pepper) Mohit Aghera (mohit_aghera) Benji Fisher (benjifisher) catch (catch) Lee Rowlands (larowlan) Juraj Nemec (poker10) Jess (xjm)