CVE-2026-81161 PUBLISHED

Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107

Assigner: drupal
Reserved: 26.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.

Product Status

Vendor Drupal
Product Content Moderation Notifications
Versions
  • affected from 0.0.0 to 3.9.0 (excl.)

Credits

  • Lee Rowlands (larowlan) finder
  • Luke Leber (luke.leber) finder
  • Brian Osborne (bkosborne) remediation developer
  • Jonathan Hedstrom (jhedstrom) remediation developer
  • Luke Leber (luke.leber) remediation developer
  • Swan Kalata (akalata) coordinator
  • Greg Knaddison (greggles) coordinator
  • Lee Rowlands (larowlan) coordinator
  • Juraj Nemec (poker10) coordinator

References

Problem Types

  • CWE-267 Privilege Defined With Unsafe Actions CWE

Impacts

  • CAPEC-233 Privilege Escalation