CVE-2026-15916
Project: Drupal core Date: 2026-July-15 Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon Vulnerability: Information disclosure Affected versions: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.* CVE IDs: CVE-2026-15916 Description: The Image module allows you to define and configure image fields. The module doesn't sufficiently check access to image style derivatives when those files are served via a file stream other than private:// . This vulnerability is mitigated by the fact that Drupal must be configured to use a contributed (non-core) file scheme to serve private derived images. Information disclosure issues like this one are not generally given security advisories (as described in PSA-2023-07-12) ). This fix is provided as a hardening. Contributed modules implementing custom stream wrappers may need to add similar hardenings. Solution: Install the latest version: Drupal 11 If you use Drupal 11.4.x, update to Drupal 11.4.4 . If you use Drupal 11.3.x, update to Drupal 11.3.14 . Drupal 11.2.x and below are end-of-life and do not receive security coverage. Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.13 . Drupal 10.5.x and below are end-of-life and do not receive security coverage. Drupal 8 and Drupal 9 have both reached end-of-life. Reported By: offensive-ai Fixed By: Benji Fisher (benjifisher) of the Drupal Security Team Kim Pepper (kim.pepper) Mohit Aghera (mohit_aghera) Coordinated By: Benji Fisher (benjifisher) of the Drupal Security Team catch (catch) of the Drupal Security Team Lee Rowlands (larowlan) of the Drupal Security Team Juraj Nemec (poker10) of the Drupal Security Team Jess (xjm) of the Drupal Security Team
CSIRTS triage
- What
- The Image module does not sufficiently check access to image style derivatives, leading to potential information disclosure.
- Who is affected
- Deployments of Drupal core versions listed above that are configured to use a contributed file scheme for serving private derived images are affected.
- Urgency
- Remediation is urgent due to the critical severity of the vulnerability, although exploitation requires specific configuration.
- Action
- Update to the latest version of Drupal to address this hardening issue.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-15916
Get an email if CVE-2026-15916 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Advisory coverage (3)
- medium[NEW] [medium] Drupal Core: Multiple vulnerabilitiescert-bund · 2026-07-16
- unknownMultiple vulnerabilities in Drupal (July 16, 2026)cert-fr-avis · 2026-07-16
- criticalDrupal core - Moderately critical - Information disclosure - SA-CORE-2026-010drupal · 2026-07-15
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-15916)