Drupal CMN Privilege Escalation via Unsafe Actions (3.9.0)
CVE-2026-81161 Published on September 2, 2026
Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
Vulnerability Analysis
CVE-2026-81161 can be exploited with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Privilege Defined With Unsafe Actions
A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.
Affected Versions
Drupal Content Moderation Notifications:- Version 0.0.0 and below 3.9.0 is affected.