DRUPAL-CONTRIB-2026-217

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/advanced_filesystem/DRUPAL-CONTRIB-2026-217.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-217
Aliases
  • CVE-2026-107262
Published
2026-10-07T16:58:12Z
Modified
2026-10-07T20:15:05Z
Summary
[none]
Details

Advanced File System turns Drupal's file storage into a manageable, observable and maintainable subsystem.

The Advanced Filesystem: Backup submodule does not sufficiently validate certain requests. This may allow an attacker to trick an authenticated user into performing unintended actions through a Cross-Site Request Forgery (CSRF) vulnerability.

The vulnerability is mitigated by the fact that advanced_filesystem_backup module must be enabled.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/advanced_filesystem

Package

Name
drupal/advanced_filesystem
Purl
pkg:composer/drupal/advanced_filesystem?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.28
Database specific
Show details
{
    "constraint": "<1.0.28"
}

Database specific

affected_versions
"<1.0.28"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/advanced_filesystem/DRUPAL-CONTRIB-2026-217.json"