SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15916

MEDIUM · CVSS 4.2 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A missing authorization vulnerability in Drupal core allows for forceful browsing, potentially enabling unauthorized access to restricted content. This issue affects multiple versions of Drupal core, specifically from 0.0.0 up to 10.6.13 and various 11.x releases. Organizations using affected versions should prioritize remediation to prevent unauthorized data exposure.

CVE
CVE-2026-15916
Severity
MEDIUM
CVSS
4.2
EPSS
0.12%

Original NVD Description

Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.