CVE-2026-13235
Critical · CVSS 9.8Drupal AI (Artificial Intelligence) module — Missing Authorization / Forceful Browsing (CWE-862)
- CVSS
- 9.8
- nvd
- EPSS
- 0.14%
- 4th pct
- KEV
- No
- Class
- oss containerizable
- CWE-862
Description
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.
Search profile — drives PoC discovery
Symbols drupal/aisa-contrib-2026-055AI (Artificial Intelligence)packages.drupal.org/8Forceful BrowsingCWE-862
Keywords CVE-2026-13235Drupal AI moduleMissing AuthorizationForceful Browsingdrupal/aisa-contrib-2026-055Drupal AI exploitDrupal AI PoCCWE-862 Drupal
Versions: 0.0.0 to 1.2.17, 1.3.0 to 1.3.8, 1.4.0 to 1.4.3
Affected packages
| Packagist:https://packages.drupal.org/8 | drupal/ai | 0 → 1.2.17 |
| Packagist:https://packages.drupal.org/8 | drupal/ai | 1.3.0 → 1.3.8 |
| Packagist:https://packages.drupal.org/8 | drupal/ai | 1.4.0 → 1.4.3 |
References
Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z