PT-2026-107753 · Packagist · Drupal/Advanced Filesystem

CVE-2026-107262

·

Published

2026-10-07

·

Updated

2026-10-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Advanced File System turns Drupal's file storage into a manageable, observable and maintainable subsystem.
The Advanced Filesystem: Backup submodule does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.
The vulnerability is mitigated by the fact that advanced filesystem backup module must be enabled.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-107262
DRUPAL-CONTRIB-2026-217

Affected Products

Drupal/Advanced Filesystem