PT-2026-48592 · Drupal+2 · Examples For Developers+2

·

CVE-2026-11909

·

Published

2026-06-10

·

Updated

2026-07-10

CVSS v3.1

3.3

Low

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Examples for Developers versions 0.0.0 through 4.0.6
Description A missing authorization issue allows forceful browsing. Specifically, the "Read from a file" feature within the file example submodule can be used to expose any file that PHP can access, leading to an access bypass.
Recommendations Remove the file example submodule from Examples for Developers versions 0.0.0 through 4.0.6. Developers who based a new module on this example should review their code for an access bypass.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11909
DRUPAL-CONTRIB-2026-044

Affected Products

Examples For Developers
Drupal/Examples
Examples