CVE-2026-13235: AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal AI (Artificial Intelligence)to a version that resolves this vulnerability.Fixed in 1.2.17 - Upgrade
Upgrade
Drupal AI (Artificial Intelligence)to a version that resolves this vulnerability.Fixed in 1.3.8 - Upgrade
Upgrade
Drupal AI (Artificial Intelligence)to a version that resolves this vulnerability.Fixed in 1.4.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13235?
The severity of CVE-2026-13235 is rated low, with a score of 3.3.
How do I fix CVE-2026-13235?
To fix CVE-2026-13235, update your AI (Artificial Intelligence) version to any version beyond 1.4.3.
What vulnerability does CVE-2026-13235 address?
CVE-2026-13235 addresses a Missing Authorization vulnerability that allows Forceful Browsing in specified versions of Drupal AI.
Which versions of AI (Artificial Intelligence) are affected by CVE-2026-13235?
CVE-2026-13235 affects AI (Artificial Intelligence) versions from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, and from 1.4.0 to 1.4.3.
Is CVE-2026-13235 a critical vulnerability?
CVE-2026-13235 is considered moderately critical, with potential risks associated with unauthorized access.