Executive brief
WissKI is a set of modules for Drupal used to create semantic research environments, primarily in the digital humanities. A security flaw in the Mirador viewer component allows unauthorized users to bypass access controls by manipulating specific web requests. This could allow an attacker to view or modify data they should not have access to, potentially compromising the integrity of research data.
Technical details
A missing authorization vulnerability exists in the wisski_mirador submodule of the Drupal WissKI project. The vulnerability stems from a failure to sufficiently validate submitted parameters on a specific route before writing them to the session object. An unauthenticated attacker can exploit this via forceful browsing to achieve an access bypass. The issue affects all versions prior to 4.2.0 and has been addressed in version 8.x-4.2 (and subsequently 4.3). The Drupal Security Team classified this as Critical with a risk score of 17/25.
Affected products
- Drupal WissKI 0.0.0 to 4.1.9
Timeline
- 2026-06-23: patched: Version 8.x-4.3 released
- 2026-06-24: advisory: Drupal security advisory SA-CONTRIB-2026-059 published
- 2026-07-10: disclosed: CVE-2026-13239 published to NVD