PT-2026-60353 · Drupal+2 · Drupal Core+1

·

CVE-2026-15916

·

Published

2026-07-15

·

Updated

2026-08-26

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal core versions 0.0.0 through 10.6.13 Drupal core versions 11.3.0 through 11.3.14 Drupal core versions 11.4.0 through 11.4.4 Drupal core versions 0.0.0 through 11.0.x Drupal core versions 0.0.0 through 11.1.x Drupal core versions 0.0.0 through 11.2.x
Description A missing authorization issue in the Image module allows forceful browsing, leading to information disclosure. The module fails to sufficiently check access to image style derivatives when files are served via a file stream other than private://. This issue occurs when Drupal is configured to use a contributed file scheme to serve private derived images.
Recommendations Update versions 0.0.0 through 10.6.13 to a newer version. Update versions 11.3.0 through 11.3.14 to a newer version. Update versions 11.4.0 through 11.4.4 to a newer version. Update versions 0.0.0 through 11.0.x to a newer version. Update versions 0.0.0 through 11.1.x to a newer version. Update versions 0.0.0 through 11.2.x to a newer version.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15916
DRUPAL-CORE-2026-010

Affected Products

Drupal Core
Drupal