Executive brief
The Ray Enterprise Translation module for Drupal, which automates website translation services, contains a security flaw that could allow an attacker to perform unauthorized administrative actions. By tricking a logged-in administrator into clicking a malicious link, an attacker could change translation settings, upload or download content, or modify the status of translation projects without the user's consent. This could lead to unauthorized content changes or disruption of the translation workflow.
Technical details
The Ray Enterprise Translation (Lingotek) module for Drupal fails to implement proper CSRF protection on several state-changing administrative routes. Specifically, the module does not validate security tokens for actions such as updating callback settings, uploading/downloading translations, or modifying translation states. An attacker can exploit this by crafting a malicious webpage or link that, when visited by an authenticated administrator, executes these actions in the context of the administrator's session. The vulnerability is mitigated by the requirement for user interaction (clicking a link) and the complexity of targeting specific administrative routes. Patches are available in versions 4.0.4, 4.1.4, and 11.0.4.
Affected products
- Drupal Ray Enterprise Translation (Lingotek) 0.0.0 to 4.0.3, 4.1.0 to 4.1.3, 11.0.0 to 11.0.3
Timeline
- 2026-07-08: advisory: Drupal security advisory SA-CONTRIB-2026-071 published
- 2026-07-10: disclosed: CVE-2026-15080 published