CVE-2026-1554: Central Authentication System (CAS) Server - Less critical - XML Element Injection - SA-CONTRIB-2026-007
XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1554?
CVE-2026-1554 is classified as a less critical vulnerability in the Central Authentication System (CAS) Server.
How do I fix CVE-2026-1554?
To fix CVE-2026-1554, update the Central Authentication System (CAS) Server to a version higher than 2.1.2.
What impact does CVE-2026-1554 have on my system?
CVE-2026-1554 allows for privilege escalation through XML element injection, potentially compromising user permissions.
Which versions of the Central Authentication System (CAS) Server are affected by CVE-2026-1554?
CVE-2026-1554 affects Central Authentication System (CAS) Server versions from 0.0.0 up to, but not including, 2.0.3 and versions from 2.1.0 up to, but not including, 2.1.2.
Is CVE-2026-1554 a common vulnerability in Drupal?
CVE-2026-1554 is identified as a specific vulnerability impacting the Central Authentication System (CAS) Server in Drupal.