CVE-2026-13232

CVE-2026-13232: Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access bypass / Insecure Direct Object Reference (IDOR) - SA-CONTRIB-2026-052

Vendor Drupal
Product Advanced Content Feedback (aka admin_feedback)
Weakness CWE-863 · Incorrect authorization
Published July 10, 2026
Last update July 10, 2026

CVSS base score

What the vulnerability does

01Description

Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.

Key dates

02Disclosure timeline

July 10, 2026 CVE published

Related vulnerabilities

04Related CVE