CVE-2026-73478 PUBLISHED

Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096

Assigner: drupal
Reserved: 12.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.

Product Status

Vendor Drupal
Product Diff
Versions
  • affected from 0.0.0 to 2.0.1 (excl.)
  • affected from 2.1.0 to 2.1.1 (excl.)

Credits

  • Alexei Rayu (alexrayu) finder
  • Adam Bramley (acbramley) remediation developer
  • Derek Wright (dww) remediation developer
  • Lee Rowlands (larowlan) remediation developer
  • Swan Kalata (akalata) coordinator
  • Greg Knaddison (greggles) coordinator
  • Lee Rowlands (larowlan) coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE

Impacts

  • CAPEC-87 Forceful Browsing