CVE-2026-15916
published 2026-08-25CVE-2026-15916: Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0…
PriorityP422medium4.2CVSS 3.1
AVNACHPRNUIRSUCLILAN
EPSS
0.12%
2.3th percentile
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | drupal_core | — | — |
| drupal | drupal_core | >= 0.0.0 < 10.6.13 | 10.6.13 |
| drupal | drupal_core | >= 0.0.0 < 11.0.* | 11.0.* |
| drupal | drupal_core | >= 0.0.0 < 11.1.* | 11.1.* |
| drupal | drupal_core | >= 0.0.0 < 11.2.* | 11.2.* |
| drupal | drupal_core | >= 11.3.0 < 11.3.14 | 11.3.14 |
| drupal | drupal_core | >= 11.4.0 < 11.4.4 | 11.4.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Drupal
Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
vendor_drupal·2026-07-15
CVE-2026-15916 [MEDIUM] Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
Title: Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
Vulnerability Type: Information disclosure
Description: The Image module allows you to define and configure image fields. The module doesn't sufficiently check access to image style derivatives when those files are served via a file stream other than private:// . This vulnerability is mitigated by the fact that Drupal must be configured to use a contributed (non-core) file scheme to serve private derived images. Information disclosure issues like this one are not generally given security advisories (as described in PSA-2023-07-12) ). This fix is provided as a hardening. Contributed modules implementing custom stream wrappers may need to add similar hardenings.
Solution: Install the latest version: Drupa
GHSA
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.
ghsa_unreviewed·2026-08-26
CVE-2026-15916 CWE-862 Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing.
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-25
Published