CVE-2026-3573: AI (Artificial Intelligence) - Moderately critical - Information Disclosure - SA-CONTRIB-2026-028
Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.1.11, from 1.2.0 before 1.2.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3573?
CVE-2026-3573 is considered moderately critical due to its potential for information disclosure.
How do I fix CVE-2026-3573?
To resolve CVE-2026-3573, update the affected AI module to version 1.1.11 or higher for versions prior to 1.1.11 and to version 1.2.12 or higher for versions prior to 1.2.0.
What types of systems are affected by CVE-2026-3573?
CVE-2026-3573 affects the Drupal AI (Artificial Intelligence) module in specified version ranges.
What does CVE-2026-3573 allow an attacker to do?
CVE-2026-3573 allows for resource injection through incorrect authorization, leading to potential information disclosure.
When was CVE-2026-3573 disclosed?
CVE-2026-3573 was disclosed as part of the security advisory SA-CONTRIB-2026-028.