CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-84915

highcovered by 1 sourcefirst seen 2026-09-03
A remote, anonymous attacker can exploit multiple vulnerabilities in various Drupal extensions to bypass access restrictions, disclose protected or sensitive content, take over user accounts, make unauthorized modifications or deletions, manipulate payment status, and conduct cross-site scripting attacks.

CSIRTS triage

What
Multiple vulnerabilities across various Drupal extensions allow remote anonymous attackers to bypass access controls, disclose protected content, take over accounts, make unauthorized modifications, manipulate payment status, and conduct XSS attacks.
Who is affected
Websites using affected Drupal extensions are at risk; anonymous attackers can exploit most vectors.
Urgency
High severity; multiple attack vectors including account takeover and payment manipulation require immediate patching.
Action
Identify and apply patches for all affected Drupal extensions listed in CVE-2026-16648, CVE-2026-81163, and CVE-2026-84910 through CVE-2026-84915.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-84915

Get an email if CVE-2026-84915 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-84915

CVE.org record

Embed the live status

CVE-2026-84915 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-84915 status](https://www.csirts.com/badge/CVE-2026-84915)](https://www.csirts.com/cve/CVE-2026-84915)