Drupal Edit_in-place Field <=2.1.1 Incorrect Authorization Forceful Browsing
CVE-2026-18985 Published on August 25, 2026
Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.
Vulnerability Analysis
CVE-2026-18985 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Types
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-18985 has been classified to as an AuthZ vulnerability or weakness.
What is an AuthZ Vulnerability?
The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-18985 has been classified to as an AuthZ vulnerability or weakness.
Affected Versions
Drupal Edit in-place field:- Version 0.0.0 and below 2.1.1 is affected.