CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.2. See the original NVD description below for full technical details.
CVE
CVE-2026-1554
Severity
MEDIUM
CVSS
4.2
EPSS
0.15%
Original NVD Description
XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.