PT-2026-63535 · Drupal+1 · Internationalization Single Sign-On+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Drupal Internationalization Single Sign-On versions 0.0.0 through 1.8.0
Description
An authentication bypass exists in the Drupal Internationalization Single Sign-On module. The module fails to sufficiently validate a short-lived token, which allows an attacker to bypass access control and authenticate as a victim user. This issue occurs in multilingual website scenarios where different domain names are used per language to enable automatic connection across domains. Exploitation requires the attacker to appear to originate from the same client IP address as the victim.
Recommendations
Update Drupal Internationalization Single Sign-On to a version later than 1.8.0.
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internationalization Single Sign-On
Drupal/I18N Sso