[NEW] [high] Drupal Extensions: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in various Drupal extensions to bypass security measures, disclose sensitive information, manipulate data, and conduct cross-site scripting attacks.
CSIRTS triage
- What
- Multiple vulnerabilities across various Drupal extensions enable authentication bypass, information disclosure, data manipulation, and cross-site scripting.
- Who is affected
- Drupal sites using one or more of the affected extensions are vulnerable.
- Urgency
- High priority; authentication bypass combined with XSS and information disclosure can lead to site compromise.
- Action
- Identify which specific Drupal extensions are affected and update each to their respective patched versions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Drupal Extensions
Get an email when a new Drupal Extensions advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3041
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-81158 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81159 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81160 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81161 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81162 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81164 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81165 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81166 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81167 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81168 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81201 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81205 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81269 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-81269: Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue …nvd
- mediumCVE-2026-81205: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerabi…nvd
- mediumCVE-2026-81201: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerabi…nvd
- lowCVE-2026-81168: Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Prote…nvd
- mediumCVE-2026-81167: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerabi…nvd
- mediumCVE-2026-81166: Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsi…nvd
- mediumCVE-2026-81165: Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue aff…nvd
- mediumCVE-2026-81164: Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue …nvd
- mediumCVE-2026-81162: Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Be…nvd
- lowCVE-2026-81161: Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications…nvd
- mediumCVE-2026-81160: Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerabi…nvd
- lowCVE-2026-81159: Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force.…nvd
Recent advisories for Drupal Extensions
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Drupal Extensions: Multiple Vulnerabilitiescert-bund · 2026-09-03
- medium[UPDATE] [medium] Drupal Extensions: Multiple vulnerabilitiescert-bund · 2026-07-20
- medium[NEW] [medium] Drupal Extensions: Multiple vulnerabilitiescert-bund · 2026-07-13
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] IBM i: Multiple Vulnerabilities2026-09-03
- medium[NEW] [medium] Sonatype Nexus Repository Manager: Multiple Vulnerabilities Enable Denial of Service2026-09-03
- high[NEW] [high] BigBlueButton: Multiple Vulnerabilities2026-09-03
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-09-03
- medium[NEW] [medium] Red Hat Enterprise Linux (libsolv, aardvark-dns): Multiple vulnerabilities2026-09-03