SA-CONTRIB-2026-176: Critical severity drupal/cloud vulnerability
The Cloud module enables users to manage cloud infrastructure through Drupal. The Kubernetes and VMware integrations do not properly validate TLS certificates when connecting to remote API endpoints. An attacker who can intercept these connections may obtain secret tokens or other credentials, potentially allowing unauthorized access to the connected infrastructure.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/cloudto a version that resolves this vulnerability.Fixed in 7.0.1
Event History
Frequently Asked Questions
Who is exposed to this issue?
Drupal sites using the Cloud module's Kubernetes or VMware integrations are exposed when those integrations connect to remote API endpoints.
What does an attacker need to exploit it?
An attacker must be able to intercept connections between the affected integration and its remote API endpoint. Successful interception may expose secret tokens or other credentials.
What could compromise of these credentials allow?
Obtained tokens or credentials could allow unauthorized access to the connected Kubernetes or VMware infrastructure.