PT-2026-5204 · Drupal · Drupal Entity Share

Bram Driesen

+8

·

Published

2026-01-28

·

Updated

2026-02-06

·

CVE-2025-13985

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Drupal Entity Share versions prior to 3.13.0
Description An authorization issue exists in Drupal Entity Share that permits forceful browsing. This flaw potentially allows unauthorized access to resources.
Recommendations Update Drupal Entity Share to version 3.13.0 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13985
DRUPAL-CONTRIB-2025-123

Affected Products

Drupal Entity Share