CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-13237

Critical · CVSS 9.1

Drupal AI Agents (drupal/ai_agents) — Incorrect Authorization / Forceful Browsing (CWE-863)

CVSS
9.1
nvd
EPSS
0.14%
4th pct
KEV
No
Class
oss containerizable
CWE-863

Description

Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.

Search profile — drives PoC discovery

Symbols ai_agentsdrupal/ai_agentssa-contrib-2026-057AI AgentsForceful BrowsingCWE-863
Keywords CVE-2026-13237drupal ai_agents incorrect authorizationdrupal ai_agents forceful browsingdrupal/ai_agents exploitSA-CONTRIB-2026-057drupal ai_agents CWE-863ai_agents authorization bypass PoCdrupal ai agents 1.1.4 1.2.5 1.3.1 vulnerability
Versions: 0.0.0 to 1.1.4, 1.2.0 to 1.2.5, 1.3.0 to 1.3.1

Affected packages

Packagist:https://packages.drupal.org/8 drupal/ai_agents 0 → 1.1.4
Packagist:https://packages.drupal.org/8 drupal/ai_agents 1.2.0 → 1.2.5
Packagist:https://packages.drupal.org/8 drupal/ai_agents 1.3.0 → 1.3.1

References

Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z