CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010

criticalCVE-2026-15916
Project: Drupal core Date: 2026-July-15 Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon Vulnerability: Information disclosure Affected versions: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.* CVE IDs: CVE-2026-15916 Description: The Image module allows you to define and configure image fields. The module doesn't sufficiently check access to image style derivatives when those files are served via a file stream other than private:// . This vulnerability is mitigated by the fact that Drupal must be configured to use a contributed (non-core) file scheme to serve private derived images. Information disclosure issues like this one are not generally given security advisories (as described in PSA-2023-07-12) ). This fix is provided as a hardening. Contributed modules implementing custom stream wrappers may need to add similar hardenings. Solution: Install the latest version: Drupal 11 If you use Drupal 11.4.x, update to Drupal 11.4.4 . If you use Drupal 11.3.x, update to Drupal 11.3.14 . Drupal 11.2.x and below are end-of-life and do not receive security coverage. Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.13 . Drupal 10.5.x and below are end-of-life and do not receive security coverage. Drupal 8 and Drupal 9 have both reached end-of-life. Reported By: offensive-ai Fixed By: Benji Fisher (benjifisher) of the Drupal Security Team Kim Pepper (kim.pepper) Mohit Aghera (mohit_aghera) Coordinated By: Benji Fisher (benjifisher) of the Drupal Security Team catch (catch) of the Drupal Security Team Lee Rowlands (larowlan) of the Drupal Security Team Juraj Nemec (poker10) of the Drupal Security Team Jess (xjm) of the Drupal Security Team

CSIRTS triage

vendor: Drupalproduct: Drupal coreInformation disclosureaffected: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.*
What
The Image module does not sufficiently check access to image style derivatives, leading to potential information disclosure.
Who is affected
Deployments of Drupal core versions listed above that are configured to use a contributed file scheme for serving private derived images are affected.
Urgency
Remediation is urgent due to the critical severity of the vulnerability, although exploitation requires specific configuration.
Action
Update to the latest version of Drupal to address this hardening issue.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Drupal core

Get an email when a new Drupal core advisory drops — max one per day, one-click unsubscribe.

Details

Source
Drupal Security Advisories (INTL · vendor-psirt · site)
Severity
critical
Published
2026-07-15
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.drupal.org/sa-core-2026-010

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-15916coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Drupal core -

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Drupal Security Advisories