Drupal admin_feedback V02.8.0 Incorrect Auth Forceful Browsing
CVE-2026-13232 Published on July 10, 2026
Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access bypass / Insecure Direct Object Reference (IDOR) - SA-CONTRIB-2026-052
Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.
Vulnerability Analysis
CVE-2026-13232 is exploitable with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and no impact on availability.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-13232 has been classified to as an AuthZ vulnerability or weakness.
Affected Versions
Drupal Advanced Content Feedback (aka admin_feedback):- Version 0.0.0 and below 2.8.0 is affected.