CVE-2026-0748 PUBLISHED

Access bypass in Drupal 7 i18n_node translation UI

Assigner: drupal
Reserved: 08.01.2026 Published: 26.03.2026 Updated: 27.03.2026

In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" and "Administer content translations" permissions to view and attach unpublished nodes via the translation UI and its autocomplete widget. This bypasses intended access controls and discloses unpublished node titles and IDs.

Exploit affects versions 7.x-1.0 up to and including 7.x-1.35.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Drupal
Product Internationalization (i18n) - i18n_node submodule
Versions Default: unaffected
  • affected from 7.x-1.0 to 7.x-1.35 (incl.)

Credits

  • Tatár Balázs János (tatarbj) finder

References

Problem Types

  • CWE-284 Improper Access Control CWE

Impacts

  • CAPEC-233 Privilege Abuse