CVE-2026-15083: ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal ECA: Event - Condition - Actionto a version that resolves this vulnerability.Fixed in 2.1.20 - Upgrade
Upgrade
Drupal ECA: Event - Condition - Actionto a version that resolves this vulnerability.Fixed in 3.0.12 - Upgrade
Upgrade
Drupal ECA: Event - Condition - Actionto a version that resolves this vulnerability.Fixed in 3.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15083?
CVE-2026-15083 has a risk rating of 60, indicating a less critical level of severity.
How do I fix CVE-2026-15083?
To fix CVE-2026-15083, upgrade to the latest version of ECA: Event - Condition - Action that is not affected by this vulnerability.
Which versions of ECA: Event - Condition - Action are affected by CVE-2026-15083?
CVE-2026-15083 affects ECA: Event - Condition - Action versions from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, and from 3.1.0 to 3.1.4.
What type of vulnerability is CVE-2026-15083?
CVE-2026-15083 is categorized as an Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability.
What impact does CVE-2026-15083 have on Drupal ECA: Event - Condition - Action?
CVE-2026-15083 allows Object Injection, leading to potential information disclosure within the affected Drupal modules.