Bug 2451985 (CVE-2026-0748)
| Summary: | CVE-2026-0748 Drupal 7: i18n: i18n_node: Drupal 7 i18n module: Information disclosure of unpublished nodes via translation UI | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Drupal 7 Internationalization (i18n) module, specifically within its i18n_node submodule. A user possessing both "Translate content" and "Administer content translations" permissions can exploit this vulnerability. By utilizing the translation user interface (UI) and its autocomplete widget, the user can view and attach unpublished nodes. This bypasses intended access controls, leading to the disclosure of unpublished node titles and their unique identifiers.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2452008, 2452007 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-03-26 22:02:12 UTC
|