Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4172 articles · 197414 vulns · 37/41 feeds (7d)
← Back to list
5.9
CVE-2026-11914
drupal · composer

Composer - Critical - Unsupported - SA-CONTRIB-2026-046

Description

vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.

Affected Products

VendorProductVersions
drupalcomposer*.*

References

  • https://www.drupal.org/sa-contrib-2026-046

Related News (2 articles)

Tier C
VulDB46d ago
CVE-2026-11914 | Drupal Composer Local Privilege Escalation
→ No new info (linked only)
Tier B
BSI Advisories75d ago
[NEU] [mittel] Drupal: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.15.9 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
PublishedJul 10, 2026
Last enriched45d agov2
Trending Score0
Source articles2
Independent2
Info Completeness6/14
Missing: cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-55803EXP
Drupal core - Critical - PHP object injection - SA-CORE-2026-005
Trending: 24
CRITICALPRE-CVE
Drupal Internationalization Single Sign-On Access Bypass
Trending: 1
CRITICALCVE-2026-11913
Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045
Trending: 1
MEDIUMCVE-2026-15083EXP
ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074
LOWCVE-2026-55807EXP
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026
Updated: description, severity
Jul 10, 2026

Version History

v2
Last enriched 45d ago
v2Tier C45d ago

Updated description with details about Local Privilege Escalation and changed severity to HIGH.

descriptionseverity
via VulDB
v146d ago

Initial creation