Junglewise Threat Intelligence

CVE-2026-11914: Drupal Composer module unpatched vulnerability and end of support

CVE-2026-11914 · Severity: info · CVSS 7.2 · Published 2026-07-10

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Composer module for Drupal, which allows administrators to manage PHP dependencies through the Drush command-line tool, has been marked as unsupported due to an unpatched security vulnerability. Because the maintainer has not addressed the issue, the Drupal security team has issued a critical advisory recommending that all users immediately uninstall the module. Continued use of this module could allow an attacker with administrative access to compromise the entire website and its data.

Technical details

The Drupal security team has marked the Composer module (a Drush extension) as unsupported due to a critical, unpatched security vulnerability. While the specific vulnerability class was not detailed in the advisory, it is rated as 'Critical' (16/25 on the Drupal risk scale) and affects all versions of the module. The vulnerability requires administrative privileges to exploit but can lead to a full compromise of Confidentiality, Integrity, and Availability. This issue is specific to the Drupal module and does not affect the core Composer PHP dependency manager itself. Since the project is abandoned, no patch is expected; users must migrate to alternative dependency management workflows.

Affected products

  • Drupal Composer (Drupal Module) All versions

Timeline

  • 2026-06-10: disclosed: Drupal security team marked the project as unsupported due to an unpatched security issue.
  • 2026-07-10: advisory: CVE-2026-11914 published.

References