CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-15916

criticalcovered by 3 sourcesfirst seen 2026-07-15
Project: Drupal core Date: 2026-July-15 Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon Vulnerability: Information disclosure Affected versions: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.* CVE IDs: CVE-2026-15916 Description: The Image module allows you to define and configure image fields. The module doesn't sufficiently check access to image style derivatives when those files are served via a file stream other than private:// . This vulnerability is mitigated by the fact that Drupal must be configured to use a contributed (non-core) file scheme to serve private derived images. Information disclosure issues like this one are not generally given security advisories (as described in PSA-2023-07-12) ). This fix is provided as a hardening. Contributed modules implementing custom stream wrappers may need to add similar hardenings. Solution: Install the latest version: Drupal 11 If you use Drupal 11.4.x, update to Drupal 11.4.4 . If you use Drupal 11.3.x, update to Drupal 11.3.14 . Drupal 11.2.x and below are end-of-life and do not receive security coverage. Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.13 . Drupal 10.5.x and below are end-of-life and do not receive security coverage. Drupal 8 and Drupal 9 have both reached end-of-life. Reported By: offensive-ai Fixed By: Benji Fisher (benjifisher) of the Drupal Security Team Kim Pepper (kim.pepper) Mohit Aghera (mohit_aghera) Coordinated By: Benji Fisher (benjifisher) of the Drupal Security Team catch (catch) of the Drupal Security Team Lee Rowlands (larowlan) of the Drupal Security Team Juraj Nemec (poker10) of the Drupal Security Team Jess (xjm) of the Drupal Security Team

CSIRTS triage

vendor: Drupalproduct: Drupal coreInformation disclosureaffected: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.*
What
The Image module does not sufficiently check access to image style derivatives, leading to potential information disclosure.
Who is affected
Deployments of Drupal core versions listed above that are configured to use a contributed file scheme for serving private derived images are affected.
Urgency
Remediation is urgent due to the critical severity of the vulnerability, although exploitation requires specific configuration.
Action
Update to the latest version of Drupal to address this hardening issue.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-15916

Get an email if CVE-2026-15916 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (3)

External references

NVD record for CVE-2026-15916

CVE.org record

Embed the live status

CVE-2026-15916 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-15916 status](https://www.csirts.com/badge/CVE-2026-15916)](https://www.csirts.com/cve/CVE-2026-15916)