Drupal i18n SSO Authentication Bypass v<1.8.0 via Alternate Path
CVE-2026-16639 Published on August 25, 2026
Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
Vulnerability Analysis
CVE-2026-16639 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
Affected Versions
Drupal Internationalization Single Sign-On:- Version 0.0.0 and below 1.8.0 is affected.