CVE-2026-58590: FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068
Published Jul 10, 2026
·Updated
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
Affected Software
2 affected components
Drupal FlowDrop>=0.0.0<=1.6.0
Flowdrop Project Flowdrop Drupal<1.6.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal FlowDropto a version that resolves this vulnerability.Fixed in 1.6.0Patch SA-CONTRIB-2026-068
Event History
Jul 10, 2026
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-58590?
CVE-2026-58590 is rated as moderately critical.
2
How do I fix CVE-2026-58590?
To fix CVE-2026-58590, upgrade FlowDrop to version 1.6.1 or later.
3
What software is affected by CVE-2026-58590?
CVE-2026-58590 affects all versions of FlowDrop from 0.0.0 to 1.6.0.
4
What type of vulnerability is CVE-2026-58590?
CVE-2026-58590 is an access bypass vulnerability allowing forceful browsing.
5
When was CVE-2026-58590 published?
CVE-2026-58590 was published on July 10, 2026.