CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-13235

Critical · CVSS 9.8

Drupal AI (Artificial Intelligence) module — Missing Authorization / Forceful Browsing (CWE-862)

CVSS
9.8
nvd
EPSS
0.14%
4th pct
KEV
No
Class
oss containerizable
CWE-862

Description

Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.

Search profile — drives PoC discovery

Symbols drupal/aisa-contrib-2026-055AI (Artificial Intelligence)packages.drupal.org/8Forceful BrowsingCWE-862
Keywords CVE-2026-13235Drupal AI moduleMissing AuthorizationForceful Browsingdrupal/aisa-contrib-2026-055Drupal AI exploitDrupal AI PoCCWE-862 Drupal
Versions: 0.0.0 to 1.2.17, 1.3.0 to 1.3.8, 1.4.0 to 1.4.3

Affected packages

Packagist:https://packages.drupal.org/8 drupal/ai 0 → 1.2.17
Packagist:https://packages.drupal.org/8 drupal/ai 1.3.0 → 1.3.8
Packagist:https://packages.drupal.org/8 drupal/ai 1.4.0 → 1.4.3

References

Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z