Drupal · Examples For Developers · CVE-2026-11909
**Name of the Vulnerable Software and Affected Versions**
Examples for Developers versions 0.0.0 through 4.0.6
**Description**
A missing authorization issue allows forceful browsing. Specifically, the "Read from a file" feature within the `file example` submodule can be used to expose any file that PHP can access, leading to an access bypass.
**Recommendations**
Remove the `file example` submodule from Examples for Developers versions 0.0.0 through 4.0.6.
Developers who based a new module on this example should review their code for an access bypass.