PT-2026-23110 · Drupal+2 · Ajax Dashboard+1

Bram Driesen

+3

·

Publicado

2026-03-04

·

Atualizado

2026-03-26

·

CVE-2026-3527

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal AJAX Dashboard versions prior to 3.1.0
Description A missing authentication check for a critical function in Drupal AJAX Dashboard allows exploitation of incorrectly configured access control security levels. The issue resides in the AJAX Dashboard module, specifically related to entity dashboards enabling configurable dashboards attached to entities with AJAX-reloading capabilities. The module does not adequately verify access permissions on the dashboard configuration route, potentially allowing unauthorized users to access and modify dashboard settings. The vulnerability is mitigated if the AJAX Dashboard Entity Dashboard submodule is not enabled.
Recommendations Update to AJAX Dashboard version 3.1.0 or later.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3527
DRUPAL-CONTRIB-2026-022

Produtos afetados

Ajax Dashboard
Drupal/Ajax Dashboard