Drupal · Drupal · CVE-2026-4933
**Name of the Vulnerable Software and Affected Versions**
Drupal versions prior to 1.7.0
**Description**
An incorrect authorization issue exists in Drupal’s Unpublished Node Permissions, allowing forceful browsing. The problem relates to inconsistent access control for unpublished translated nodes. The module, designed to manage permissions for unpublished nodes per content type, does not consistently enforce these controls.
**Recommendations**
Update to version 1.7.0 or later.