Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2026-006 |
|
Wed, 11 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal Canvas Project
Drupal Canvas Project drupal Canvas |
|
| CPEs | cpe:2.3:a:drupal_canvas_project:drupal_canvas:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Drupal Canvas Project
Drupal Canvas Project drupal Canvas |
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal
Drupal canvas |
|
| Vendors & Products |
Drupal
Drupal canvas |
Wed, 04 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 04 Feb 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas: from 0.0.0 before 1.0.4. | |
| Title | Drupal Canvas - Moderately critical - Access bypass - SA-CONTRIB-2026-006 | |
| Weaknesses | CWE-863 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2026-02-04T21:21:35.681Z
Reserved: 2026-01-28T17:01:08.406Z
Link: CVE-2026-1553
Updated: 2026-02-04T21:21:32.635Z
Status : Analyzed
Published: 2026-02-04T21:15:59.267
Modified: 2026-02-11T19:19:03.170
Link: CVE-2026-1553
No data.
OpenCVE Enrichment
Updated: 2026-04-17T23:15:30Z