SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16639

CRITICAL · CVSS 9.8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in the Internationalization Single Sign-On module for Drupal allows for authentication bypass, enabling unauthorized access to user accounts. This affects all versions from 0.0.0 to 1.8.0, making it critical for organizations using this module to prioritize patching to prevent potential exploitation. Drupal administrators and security teams should assess their systems for this vulnerability and implement necessary updates.

CVE
CVE-2026-16639
Severity
CRITICAL
CVSS
9.8
EPSS
0.35%

Original NVD Description

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.