CVE-2026-3573
AI (Artificial Intelligence) - Moderately critical - Information Disclosure - SA-CONTRIB-2026-028
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
4th
Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.1.11, from 1.2.0 before 1.2.12.
| CWE | CWE-863 |
| Vendor | drupal |
| Product | ai (artificial intelligence) |
| Ecosystems | |
| Industries | WebMedia |
| Published | Mar 26, 2026 |
| Last Updated | Mar 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for drupal ai (artificial intelligence)
Be the first to know when new high vulnerabilities affecting drupal ai (artificial intelligence) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Drupal / AI (Artificial Intelligence)
0.0.0 < 1.1.11 1.2.0 < 1.2.12
Credits
Marcus Johansson (marcus_johansson) Artem Dmitriiev (a.dmitriiev) Abhisek Mazumdar (abhisekmazumdar) Dave Long (longwave) Marcus Johansson (marcus_johansson) Valery Lourie (valthebald) Greg Knaddison (greggles) Drew Webber (mcdruid) Jess (xjm)