CVE-2026-13237: AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057
Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal AI Agentsto a version that resolves this vulnerability.Patch SA-CONTRIB-2026-057 - Upgrade
Upgrade
Drupal AI Agentsto a version that resolves this vulnerability.Fixed in 0.0.0Patch SA-CONTRIB-2026-057
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13237?
The severity of CVE-2026-13237 is classified as medium with a score of 4.8.
How do I fix CVE-2026-13237?
To fix CVE-2026-13237, update your Drupal AI Agents version to one that does not fall within the affected range.
What versions are affected by CVE-2026-13237?
CVE-2026-13237 affects AI Agents versions from 0.0.0 to 1.1.4, 1.2.0 to 1.2.5, and 1.3.0 to 1.3.1.
What kind of vulnerability is CVE-2026-13237?
CVE-2026-13237 is an incorrect authorization vulnerability that allows for forceful browsing.
How does CVE-2026-13237 impact my Drupal site?
CVE-2026-13237 can lead to information disclosure and unauthorized access on your Drupal site.