CVE-2026-1553: Drupal Canvas - Moderately critical - Access bypass - SA-CONTRIB-2026-006
Published Feb 4, 2026
·Updated
Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas: from 0.0.0 before 1.0.4.
Affected Software
2 affected components
drupal/drupal-canvas<1.0.4
Drupal Canvas Project Drupal Canvas Drupal<1.0.4
Event History
Feb 4, 2026
CVE Published
via MITRE·08:26 PM
Data Sourced
via MITRE·08:26 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-1553?
CVE-2026-1553 is categorized as moderately critical due to its access bypass vulnerability.
2
How do I fix CVE-2026-1553?
To fix CVE-2026-1553, update Drupal Canvas to version 1.0.4 or later.
3
What impact does CVE-2026-1553 have on Drupal Canvas?
CVE-2026-1553 allows for forceful browsing, leading to potential unauthorized access.
4
Which versions of Drupal Canvas are affected by CVE-2026-1553?
CVE-2026-1553 affects Drupal Canvas versions prior to 1.0.4.
5
Is there a patch for CVE-2026-1553?
Yes, the patch for CVE-2026-1553 is included in the update to version 1.0.4 of Drupal Canvas.