PT-2026-63535 · Drupal+1 · Internationalization Single Sign-On+1

·

CVE-2026-16639

·

Published

2026-07-22

·

Updated

2026-08-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Drupal Internationalization Single Sign-On versions 0.0.0 through 1.8.0
Description An authentication bypass exists in the Drupal Internationalization Single Sign-On module. The module fails to sufficiently validate a short-lived token, which allows an attacker to bypass access control and authenticate as a victim user. This issue occurs in multilingual website scenarios where different domain names are used per language to enable automatic connection across domains. Exploitation requires the attacker to appear to originate from the same client IP address as the victim.
Recommendations Update Drupal Internationalization Single Sign-On to a version later than 1.8.0.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16639
DRUPAL-CONTRIB-2026-081

Affected Products

Internationalization Single Sign-On
Drupal/I18N Sso