CVE-2026-73478: Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096
Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/diffto a version that resolves this vulnerability.Fixed in 2.0.1 - Upgrade
Upgrade
drupal/diffto a version that resolves this vulnerability.Fixed in 2.1.1
Event History
Frequently Asked Questions
Which Diff installations are affected?
Affected versions are 0.0.0 through 2.0.1 and 2.1.0 through 2.1.1. The supplied information does not identify a fixed version.
Can this be exploited remotely without an account?
Yes. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the expected impact?
The vulnerability is an authorization bypass through forceful browsing and has a confidentiality impact rated Low. Integrity and availability impacts are rated None.