CVE-2026-58589: FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067
Published Jul 10, 2026
·Updated
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
Affected Software
2 affected components
Drupal FlowDrop>=0.0.0<=1.6.0
Flowdrop Project Flowdrop Drupal<=1.6.0
Event History
Jul 10, 2026
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-58589?
CVE-2026-58589 has a moderately critical risk severity rating of 48.
2
How do I fix CVE-2026-58589?
To mitigate CVE-2026-58589, update Drupal FlowDrop to version 1.6.1 or later, which addresses the missing authorization vulnerability.
3
What versions of Drupal FlowDrop are affected by CVE-2026-58589?
CVE-2026-58589 affects all versions of Drupal FlowDrop from 0.0.0 to 1.6.0.
4
What type of vulnerability is CVE-2026-58589?
CVE-2026-58589 is an access bypass vulnerability that allows for forceful browsing.
5
When was CVE-2026-58589 published?
CVE-2026-58589 was published on July 10, 2026.