CVE-2026-0748

Source
https://cve.org/CVERecord?id=CVE-2026-0748
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0748.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-0748
Published
2026-03-26T21:17:37.769Z
Modified
2026-07-15T01:49:19.142390172Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N CVSS Calculator
Summary
Access bypass in Drupal 7 i18n_node translation UI
Details

In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" and "Administer content translations" permissions to view and attach unpublished nodes via the translation UI and its autocomplete widget. This bypasses intended access controls and discloses unpublished node titles and IDs.

Exploit affects versions 7.x-1.0 up to and including 7.x-1.35.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "cna_assigner": "drupal",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0748.json"
}
References

Affected packages

Git / git.drupalcode.org/project/i18n

Affected ranges

Type
GIT
Repo
https://git.drupalcode.org/project/i18n
Events
Introduced
d104117de3d2eb66c1a54cdb75b1ee2969ce0cb2
Last affected
a6d94fe5e46ef9a3326a38742d37e792fc8b5089
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "7.x-1.0"
        },
        {
            "last_affected": "7.x-1.35"
        }
    ]
}

Affected versions

7.*
7.x-1.0
7.x-1.1
7.x-1.10
7.x-1.11
7.x-1.12
7.x-1.13
7.x-1.14
7.x-1.15
7.x-1.16
7.x-1.17
7.x-1.18
7.x-1.19
7.x-1.2
7.x-1.20
7.x-1.21
7.x-1.22
7.x-1.23
7.x-1.24
7.x-1.25
7.x-1.26
7.x-1.27
7.x-1.28
7.x-1.29
7.x-1.3
7.x-1.30
7.x-1.31
7.x-1.32
7.x-1.33
7.x-1.34
7.x-1.35
7.x-1.4
7.x-1.5
7.x-1.6
7.x-1.7
7.x-1.8
7.x-1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0748.json"