Junglewise Threat Intelligence

CVE-2026-11913: Drupal Mother May I unpatched critical vulnerability

CVE-2026-11913 · Severity: info · CVSS 7.2 · Published 2026-07-10

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The Drupal 'Mother May I' module, which is used to prevent automated bot registrations by requiring a secret word, has been marked as unsupported due to an unpatched critical security vulnerability. Because the maintainer has not addressed the flaw, the Drupal Security Team recommends uninstalling the module immediately to prevent potential site compromise. Continued use of this module may allow attackers to bypass registration protections or impact the integrity of the website.

Technical details

The Drupal Mother May I module has been issued a critical security advisory (SA-CONTRIB-2026-045) and marked as unsupported due to an unpatched vulnerability. While the specific vulnerability class (e.g., SQLi, XSS) is not explicitly detailed in the advisory, the Drupal Security Team assigned a risk score of 16/25, indicating high impact on confidentiality, integrity, and availability. The vulnerability is present in all versions of the module. Since the maintainer has failed to provide a fix, the official recommendation is to uninstall the module and seek alternative solutions for registration protection.

Affected products

  • Drupal Mother May I All versions

Timeline

  • 2026-06-10: advisory: Drupal Security Team issued SA-CONTRIB-2026-045 marking the project unsupported
  • 2026-07-10: disclosed: CVE-2026-11913 published

References