CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-10768

Critical · CVSS 9.8

drupal/localgov_workflows — Missing Authorization / Forceful Browsing (CWE-862)

CVSS
9.8
nvd
EPSS
0.33%
26th pct
KEV
No
Class
oss containerizable
CWE-862

Description

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.

Search profile — drives PoC discovery

Symbols localgov_workflowsLocalGov Workflowssa-contrib-2026-039localgov_workflows.routing.ymllocalgov_workflows.permissions.yml_access_permissionforceful_browsing
Keywords CVE-2026-10768localgov_workflowsDrupal LocalGov Workflows missing authorizationDrupal forceful browsing exploitsa-contrib-2026-039localgov_workflows PoCDrupal CWE-862 localgovlocalgov_workflows 1.6.0 vulnerability
Versions: 0.0.0 to 1.6.0

Affected packages

Packagist:https://packages.drupal.org/8 drupal/localgov_workflows 0 → 1.6.0

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z