PT-2026-107749 · Packagist · Drupal/Actstream

CVE-2026-107257

·

Published

2026-10-07

·

Updated

2026-10-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Actstream (short for Activity Stream) aggregates a user's activity from external services (RSS feeds, etc.) into per-user activity stream entities.
The configuration route does not sufficiently check that the user editing it is the account owner (or a user administrator) leading to an access bypass vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-107257
DRUPAL-CONTRIB-2026-198

Affected Products

Drupal/Actstream