CVE-2026-8495
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-862
Description
Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.
Affected packages
| Packagist:https://packages.drupal.org/8 | drupal/date_ical | 0 → 4.0.15 |
References
Status: profiled · ingested 2026-07-24T00:00:18.000Z