Description
Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas: from 0.0.0 before 1.0.4.
Problem types
CWE-863 Incorrect Authorization
Product status
0.0.0 (semver) before 1.0.4
Credits
jschref
Bálint Kléri (balintbrews)
Matt Glaman (mglaman)
Christian López EspÃnola (penyaskito)
Tim Plunkett (tim.plunkett)
Alex Bronstein (effulgentsia)
Greg Knaddison (greggles)
References
www.drupal.org/sa-contrib-2026-006