CyberRota Analysis
AI-GeneratedA missing authorization vulnerability in the FlowDrop module of Drupal allows for forceful browsing, potentially enabling unauthorized access to restricted resources. This impacts all versions from 0.0.0 to 1.6.0, and organizations using these versions should prioritize patching to mitigate the risk of unauthorized data exposure.
CVE
CVE-2026-58589
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
Original NVD Description
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)