CVE-2026-15083

CVE-2026-15083: ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074

Vendor Drupal
Product ECA: Event - Condition - Action
Weakness CWE-915
Published July 10, 2026
Last update July 10, 2026

CVSS base score

What the vulnerability does

01Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4.

Key dates

02Disclosure timeline

July 10, 2026 CVE published