PT-2026-76591 · Drupal+2 · Quick Tabs+1

·

CVE-2026-73477

·

Published

2026-08-12

·

Updated

2026-09-02

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Drupal Quick Tabs versions 0.0.0 through 4.3.1
Description An incorrect authorization issue allows forceful browsing. The module fails to correctly enforce access when rendering node and block tabs by treating neutral access results as grants for node tabs and block plugins. Additionally, no access check is performed for reusable custom blocks. This allows users without proper permissions to view restricted content, such as unpublished nodes or unpublished reusable custom blocks. The risk is limited because the content exposed is pre-selected by a user with the administer quicktabs permission during configuration.
Recommendations Update Drupal Quick Tabs to a version later than 4.3.1.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73477
DRUPAL-CONTRIB-2026-099

Affected Products

Quick Tabs
Drupal/Quicktabs