CVE-2026-13237

CVE-2026-13237: AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057

Vendor Drupal
Product AI Agents
Weakness CWE-863 · Incorrect authorization
Published July 10, 2026
Last update July 10, 2026

CVSS base score

What the vulnerability does

01Description

Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.

Key dates

02Disclosure timeline

July 10, 2026 CVE published

Related vulnerabilities

04Related CVE