SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15083

MEDIUM · CVSS 4.2 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Drupal ECA: Event - Condition - Action versions 0.0.0 to 2.1.20, 3.0.0 to 3.0.12, and 3.1.0 to 3.1.4 are vulnerable to an object injection attack due to improperly controlled modification of dynamically-determined object attributes. This vulnerability could allow an attacker to manipulate object attributes, potentially leading to unauthorized access or actions within the application. Organizations using these specific versions of Drupal ECA should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-15083
Severity
MEDIUM
CVSS
4.2
EPSS
0.18%

Original NVD Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4.