CVE-2026-11909: Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044
Published Jul 10, 2026
·Updated
Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.
Affected Software
2 affected components
Drupal>=0.0.0<=4.0.6
Rfay Examples For Developers Drupal<4.0.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/Examples for Developersto a version that resolves this vulnerability.Fixed in 4.0.6
Event History
Jul 10, 2026
CVE Published
via MITRE·09:43 PM
Data Sourced
via MITRE·09:43 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-11909?
The severity of CVE-2026-11909 is classified as low with a CVSS score of 3.3.
2
How do I fix CVE-2026-11909?
To fix CVE-2026-11909, update Examples for Developers to version 4.0.7 or later.
3
What systems are affected by CVE-2026-11909?
CVE-2026-11909 affects Examples for Developers versions from 0.0.0 to 4.0.6.
4
What kind of vulnerability is CVE-2026-11909?
CVE-2026-11909 is a missing authorization vulnerability that allows forceful browsing.
5
When was CVE-2026-11909 published?
CVE-2026-11909 was published on July 10, 2026.