CVE-2026-3527
Missing Authentication in Drupal AJAX Dashboard Enables Unauthorized Access
Publication date: 2026-03-26
Last updated on: 2026-03-31
Assigner: Drupal.org
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ceriumsoft | ajax_dashboard | to 3.1.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Missing Authentication for Critical Function issue in the Drupal AJAX Dashboard. It allows attackers to exploit incorrectly configured access control security levels, potentially enabling unauthorized access to critical functions within the AJAX Dashboard module versions before 3.1.0.
How can this vulnerability impact me? :
The impact of this vulnerability could include unauthorized users gaining access to critical functions in the Drupal AJAX Dashboard, which may lead to unauthorized actions, data exposure, or manipulation within the affected system.