PT-2026-107749 · Packagist · Drupal/Actstream

CVE-2026-107257

·

Publicado

2026-10-07

·

Atualizado

2026-10-07

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Actstream (short for Activity Stream) aggregates a user's activity from external services (RSS feeds, etc.) into per-user activity stream entities.
The configuration route does not sufficiently check that the user editing it is the account owner (or a user administrator) leading to an access bypass vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-107257
DRUPAL-CONTRIB-2026-198

Produtos afetados

Drupal/Actstream