CVE-2026-10768
drupal/localgov_workflows: Missing Authorization (CVE-2026-10768)
criticalEPSS 2.1%
Description
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
packagist:https://packages.drupal.org/8drupal/localgov_workflows
Metrics
81.4 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
critical
123.86
no public PoC known
9.8
Published
2026-07-10 21:41 UTC
CWE-862
Weakness classes (CWE)
CWE-862Class
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-08-06 15:08 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:localgovdrupal:localgov_workflows:*:*:*:*:*:drupal:*:* versions up to (excluding) 1.6.0
- Reference Type: Drupal.org: https://www.drupal.org/sa-contrib-2026-039 Types: Vendor Advisory