CVE-2026-10768

drupal/localgov_workflows: Missing Authorization (CVE-2026-10768)

criticalEPSS 2.1%

Description

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

packagist:https://packages.drupal.org/8drupal/localgov_workflows

Metrics

9.8
Source: nvd-v3
81.4 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
critical
no public PoC known
2.1 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-07-10 21:41 UTC
CWE-862

Weakness classes (CWE)

  • CWE-862Class

    Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-08-06 15:08 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:localgovdrupal:localgov_workflows:*:*:*:*:*:drupal:*:* versions up to (excluding) 1.6.0
    • Reference Type: Drupal.org: https://www.drupal.org/sa-contrib-2026-039 Types: Vendor Advisory

Linked advisories