Drupal · Wisski · CVE-2026-13239
**Name of the Vulnerable Software and Affected Versions**
WissKI versions 0.0.0 through 4.2.0
**Description**
A missing authorization issue in the `wisski mirador` submodule allows forceful browsing and access bypass. The module fails to sufficiently validate parameters submitted via a route before writing them to the session object.
**Recommendations**
Update WissKI to a version later than 4.2.0.
Restrict the use of the `wisski mirador` submodule to minimize the risk of exploitation.