CVE-2026-10768
Critical · CVSS 9.8drupal/localgov_workflows — Missing Authorization / Forceful Browsing (CWE-862)
- CVSS
- 9.8
- nvd
- EPSS
- 0.33%
- 26th pct
- KEV
- No
- Class
- oss containerizable
- CWE-862
Description
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
Search profile — drives PoC discovery
Symbols localgov_workflowsLocalGov Workflowssa-contrib-2026-039localgov_workflows.routing.ymllocalgov_workflows.permissions.yml_access_permissionforceful_browsing
Keywords CVE-2026-10768localgov_workflowsDrupal LocalGov Workflows missing authorizationDrupal forceful browsing exploitsa-contrib-2026-039localgov_workflows PoCDrupal CWE-862 localgovlocalgov_workflows 1.6.0 vulnerability
Versions: 0.0.0 to 1.6.0
Affected packages
| Packagist:https://packages.drupal.org/8 | drupal/localgov_workflows | 0 → 1.6.0 |
References
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z