PT-2026-107749 · Packagist · Drupal/Actstream
CVE-2026-107257
·
Published
2026-10-07
·
Updated
2026-10-07
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Actstream (short for Activity Stream) aggregates a user's activity from external services (RSS feeds, etc.) into per-user activity stream entities.
The configuration route does not sufficiently check that the user editing it is the account owner (or a user administrator) leading to an access bypass vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drupal/Actstream