CVE-2026-13232: Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access bypass / Insecure Direct Object Reference (IDOR) - SA-CONTRIB-2026-052
Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka adminfeedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka adminfeedback) versions: from 0.0.0 to 2.8.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal Advanced Content Feedback (aka admin_feedback)to a version that resolves this vulnerability.Fixed in 2.8.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13232?
The severity of CVE-2026-13232 is rated low with a CVSS score of 3.1.
How do I fix CVE-2026-13232?
To fix CVE-2026-13232, upgrade the Advanced Content Feedback module to version 2.8.1 or later.
What is the impact of CVE-2026-13232?
CVE-2026-13232 allows for insecure direct object references, leading to potential unauthorized access.
Which versions of the Advanced Content Feedback module are affected by CVE-2026-13232?
CVE-2026-13232 affects Advanced Content Feedback versions from 0.0.0 to 2.8.0.
What kind of vulnerability is CVE-2026-13232 classified as?
CVE-2026-13232 is classified as an access bypass vulnerability due to incorrect authorization.