CVE-2026-3526 PUBLISHED

File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-021

Assigner: drupal
Reserved: 04.03.2026 Published: 26.03.2026 Updated: 26.03.2026

Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated): from 0.0.0 before 1.2.0.

Product Status

Vendor Drupal
Product File Access Fix (deprecated)
Versions Default: unaffected
  • affected from 0.0.0 to 1.2.0 (excl.)

Credits

  • Pierre Rudloff (prudloff) finder
  • Merlin Axel Rutz (geek-merlin) remediation developer
  • Damien McKenna (damienmckenna) coordinator
  • Greg Knaddison (greggles) coordinator
  • Juraj Nemec (poker10) coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE

Impacts

  • CAPEC-87 Forceful Browsing