CVE-2026-13237
Critical · CVSS 9.1Drupal AI Agents (drupal/ai_agents) — Incorrect Authorization / Forceful Browsing (CWE-863)
- CVSS
- 9.1
- nvd
- EPSS
- 0.14%
- 4th pct
- KEV
- No
- Class
- oss containerizable
- CWE-863
Description
Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.
Search profile — drives PoC discovery
Symbols ai_agentsdrupal/ai_agentssa-contrib-2026-057AI AgentsForceful BrowsingCWE-863
Keywords CVE-2026-13237drupal ai_agents incorrect authorizationdrupal ai_agents forceful browsingdrupal/ai_agents exploitSA-CONTRIB-2026-057drupal ai_agents CWE-863ai_agents authorization bypass PoCdrupal ai agents 1.1.4 1.2.5 1.3.1 vulnerability
Versions: 0.0.0 to 1.1.4, 1.2.0 to 1.2.5, 1.3.0 to 1.3.1
Affected packages
| Packagist:https://packages.drupal.org/8 | drupal/ai_agents | 0 → 1.1.4 |
| Packagist:https://packages.drupal.org/8 | drupal/ai_agents | 1.2.0 → 1.2.5 |
| Packagist:https://packages.drupal.org/8 | drupal/ai_agents | 1.3.0 → 1.3.1 |
References
Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z