CVE-2026-13236: AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056
Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal AI Agentsto a version that resolves this vulnerability.Fixed in 1.1.4Patch SA-CONTRIB-2026-056
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13236?
The severity of CVE-2026-13236 is classified as medium with a CVSS score of 4.2.
How do I fix CVE-2026-13236?
To fix CVE-2026-13236, update your Drupal AI Agents to a version that is not affected by this vulnerability.
What versions are affected by CVE-2026-13236?
CVE-2026-13236 affects AI Agents versions from 0.0.0 to 1.1.4, 1.2.0 to 1.2.5, and 1.3.0 to 1.3.1.
What type of vulnerability is described in CVE-2026-13236?
CVE-2026-13236 describes a missing authorization vulnerability that allows forceful browsing.
Who is impacted by CVE-2026-13236?
Users of the Drupal AI Agents module within the affected versions are impacted by CVE-2026-13236.