Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
3.3
CVE-2026-11909EXPLOITEDPATCHED
drupal · examples for developers

Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044

Description

Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.

Affected Products

VendorProductVersions
drupalexamples for developers0.0.0

References

  • https://www.drupal.org/sa-contrib-2026-044

Related News (2 articles)

Tier C
VulDB44d ago
CVE-2026-11909 | Drupal Examples for Developers up to 4.0.5 Authorization authorization
→ No new info (linked only)
Tier B
BSI Advisories73d ago
[NEU] [mittel] Drupal: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.13.3 LOW
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
4.0.6
CWECWE-862
PublishedJul 10, 2026
Last enriched44d agov2
Trending Score0
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-55803EXP
Drupal core - Critical - PHP object injection - SA-CORE-2026-005
Trending: 30
CRITICALPRE-CVE
Drupal Internationalization Single Sign-On Access Bypass
Trending: 1
CRITICALCVE-2026-11913
Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045
Trending: 1
MEDIUMCVE-2026-15083EXP
ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074
LOWCVE-2026-55807EXP
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026
Updated: description, affectedVersions, severity, activelyExploited
Jul 10, 2026
Actively Exploited
Jul 13, 2026
Patch Available
Jul 13, 2026

Version History

v2
Last enriched 44d ago
v2Tier C44d ago

Updated description with more technical detail, changed affected versions to include 4.0.5, updated severity to MEDIUM, and noted that no exploit is available.

descriptionaffectedVersionsseverityactivelyExploited
via VulDB
v144d ago

Initial creation