CVE-2026-15916: Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
Published Aug 25, 2026
·Updated
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0., from 0.0.0 to 11.1., from 0.0.0 to 11.2..
Affected Software
1 affected component
Drupal Drupal Core>=0.0.0<=10.6.13, >=11.3.0<=11.3.14, >=11.4.0<=11.4.4, >0.0.0<=11.0.*, >0.0.0<=11.1.*, >0.0.0<=11.2.*
Event History
Aug 25, 2026
CVE Published
via MITRE·10:22 PM
Data Sourced
via MITRE·10:22 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Drupal core versions are affected?
Affected versions include 10.6.13 and earlier, 11.3.0 through 11.3.14, and 11.4.0 through 11.4.4. All releases in the 11.0.x, 11.1.x, and 11.2.x branches are also listed as affected.
2
Can this be exploited remotely without an account?
The CVSS vector indicates network access is possible and no privileges are required. Exploitation also has high attack complexity and requires user interaction.
3
What impact is indicated if exploitation succeeds?
The stated impact is limited information disclosure and limited integrity impact. No availability impact is indicated.