SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13237

MEDIUM · CVSS 4.8 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

An incorrect authorization vulnerability in Drupal AI Agents allows for forceful browsing, potentially enabling unauthorized access to restricted resources. This issue affects multiple versions of AI Agents, specifically from 0.0.0 to 1.1.4, 1.2.0 to 1.2.5, and 1.3.0 to 1.3.1. Organizations using these affected versions should prioritize remediation to mitigate the risk of unauthorized data exposure.

CVE
CVE-2026-13237
Severity
MEDIUM
CVSS
4.8
EPSS
0.17%

Original NVD Description

Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)