SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13236

MEDIUM · CVSS 4.2 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

A missing authorization vulnerability in Drupal AI Agents enables forceful browsing, potentially allowing unauthorized access to restricted resources. This issue impacts versions ranging from 0.0.0 to 1.3.1, making it crucial for organizations using affected versions to prioritize remediation to protect sensitive data and maintain security integrity. Users of these specific AI Agents should assess their deployments and apply necessary updates to mitigate the risk.

CVE
CVE-2026-13236
Severity
MEDIUM
CVSS
4.2
EPSS
0.14%

Original NVD Description

Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)