CVE-2026-13236
Critical · CVSS 9.8drupal/ai_agents — Missing Authorization (Forceful Browsing) CWE-862
- CVSS
- 9.8
- nvd
- EPSS
- 0.14%
- 4th pct
- KEV
- No
- Class
- oss containerizable
- CWE-862
Description
Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.
Search profile — drives PoC discovery
Symbols ai_agentsAI Agentssa-contrib-2026-056drupal/ai_agentspackages.drupal.org
Keywords CVE-2026-13236Drupal AI AgentsMissing AuthorizationForceful BrowsingCWE-862drupal ai_agents exploitsa-contrib-2026-056drupal ai agents PoCdrupal ai agents authorization bypass
Versions: 0.0.0 to 1.1.4, 1.2.0 to 1.2.5, 1.3.0 to 1.3.1
Affected packages
| Packagist:https://packages.drupal.org/8 | drupal/ai_agents | 0 → 1.1.4 |
| Packagist:https://packages.drupal.org/8 | drupal/ai_agents | 1.2.0 → 1.2.5 |
| Packagist:https://packages.drupal.org/8 | drupal/ai_agents | 1.3.0 → 1.3.1 |
References
Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z