SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-10768

CRITICAL · CVSS 9.8 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

A critical missing authorization vulnerability in Drupal LocalGov Workflows enables forceful browsing, potentially allowing unauthorized users to access restricted resources. This affects all versions from 0.0.0 to 1.6.0, posing significant risks to data integrity and confidentiality. Organizations utilizing these versions should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-10768
Severity
CRITICAL
CVSS
9.8
EPSS
0.33%

Original NVD Description

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.