Home

Description

Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue affects Role Delegation: from 1.3.0 before 1.5.0.

PUBLISHED Reserved 2026-01-14 | Published 2026-02-04 | Updated 2026-02-12 | Assigner drupal

Problem types

CWE-267 Privilege Defined With Unsafe Actions

Product status

Default status
unaffected

1.3.0 (semver) before 1.5.0
affected

Credits

Drew Webber (mcdruid) finder

Adam Bramley (acbramley) remediation developer

Dieter Holvoet (dieterholvoet) remediation developer

Greg Knaddison (greggles) coordinator

Drew Webber (mcdruid) coordinator

Juraj Nemec (poker10) coordinator

References

www.drupal.org/sa-contrib-2026-002

cve.org (CVE-2026-0945)

nvd.nist.gov (CVE-2026-0945)

Download JSON