SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-73478

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in Drupal Diff allows for forceful browsing due to incorrect authorization, potentially enabling unauthorized access to sensitive resources. Affected versions range from 0.0.0 to 2.0.1 and from 2.1.0 to 2.1.1. Organizations using these versions should prioritize remediation to protect against unauthorized data exposure.

CVE
CVE-2026-73478
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%

Original NVD Description

Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)