Bug 2451985 (CVE-2026-0748)

Summary: CVE-2026-0748 Drupal 7: i18n: i18n_node: Drupal 7 i18n module: Information disclosure of unpublished nodes via translation UI
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Drupal 7 Internationalization (i18n) module, specifically within its i18n_node submodule. A user possessing both "Translate content" and "Administer content translations" permissions can exploit this vulnerability. By utilizing the translation user interface (UI) and its autocomplete widget, the user can view and attach unpublished nodes. This bypasses intended access controls, leading to the disclosure of unpublished node titles and their unique identifiers.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2452008, 2452007    
Bug Blocks:    

Description OSIDB Bzimport 2026-03-26 22:02:12 UTC
In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" and "Administer content translations" permissions to view and attach unpublished nodes via the translation UI and its autocomplete widget. This bypasses intended access controls and discloses unpublished node titles and IDs. 

Exploit affects versions 7.x-1.0 up to and including 7.x-1.35.