CVE-2026-73478

Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.
References
Link Resource
https://www.drupal.org/sa-contrib-2026-096 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*
cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*
cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*
cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*
cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*
cpe:2.3:a:diff_project:diff:2.1.0:*:*:*:*:drupal:*:*
cpe:2.3:a:diff_project:diff:4.7.x-1.1:*:*:*:*:drupal:*:*

History

16 Sep 2026, 16:41

Type Values Removed Values Added
First Time Diff Project
Diff Project diff
CPE cpe:2.3:a:diff_project:diff:*:*:*:*:*:drupal:*:*
cpe:2.3:a:diff_project:diff:4.7.x-1.1:*:*:*:*:drupal:*:*
cpe:2.3:a:diff_project:diff:2.1.0:*:*:*:*:drupal:*:*
References () https://www.drupal.org/sa-contrib-2026-096 - () https://www.drupal.org/sa-contrib-2026-096 - Vendor Advisory

Information

Published : 2026-09-02 13:18

Updated : 2026-09-16 16:41


NVD link : CVE-2026-73478

Mitre link : CVE-2026-73478

CVE.ORG link : CVE-2026-73478


JSON object : View

Products Affected

diff_project

  • diff
CWE
CWE-863

Incorrect Authorization