πŸ” CVE Alert

CVE-2026-18985

UNKNOWN 0.0

Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.

CWE CWE-863
Vendor drupal
Product edit in-place field
Ecosystems
Industries
WebMedia
Published Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for drupal edit in-place field

Be the first to know when new unknown vulnerabilities affecting drupal edit in-place field are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

Drupal / Edit in-place field
0.0.0 < 2.1.1

References

NVD β†— CVE.org β†— EPSS Data β†—
drupal.org: https://www.drupal.org/sa-contrib-2026-093

Credits

Drew Webber (mcdruid) BÑlint Nagy (nagy.balint) Neil Drumm (drumm) Greg Knaddison (greggles)