CVE-2026-8492
MAID Vulnerability in Translate Drupal with GTranslate
Publication date: 2026-05-19
Last updated on: 2026-05-20
Assigner: Drupal.org
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| drupal | translate_drupal_with_gtranslate | From 0.0.0 (inc) to 3.0.5 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-471 | The product does not properly protect an assumed-immutable element from being modified by an attacker. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Modification of Assumed-Immutable Data (MAID) issue in the Translate Drupal with GTranslate module. It allows an attacker to perform Resource Location Spoofing, meaning that the attacker can manipulate or spoof the location of resources within the affected Drupal module.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing attackers to spoof resource locations, which may lead to users being redirected to malicious or unintended resources. This can undermine the integrity and trustworthiness of the website using the affected module.