Junglewise Threat Intelligence

CVE-2026-16643: Drupal Lunr exposed filters security issue

CVE-2026-16643 · Severity: medium · CVSS 5.7 · Published 2026-08-25

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Lunr exposed filters is a Drupal module that provides search filtering capabilities for sites using Lunr search. The maintainer has abandoned the project and did not fix a known security vulnerability, rendering the module unsupported and unsafe for use. Sites using this module should uninstall it immediately or seek alternative actively maintained solutions.

Technical details

CVE-2026-16643 represents a security vulnerability in the Drupal Lunr exposed filters module for which the maintainer has not provided a patch. The specific vulnerability details are not disclosed in available public information, but the Drupal Security Team has classified it as critical and marked the entire project as unsupported and unmaintained. The module is no longer developed, and no security fixes are expected. Organizations using this module should discontinue use and migrate to actively maintained search filtering alternatives, or engage external developers to implement security fixes and restore the module to a supported state.

Affected products

  • Drupal Lunr exposed filters all versions

Timeline

  • 2026-07-22: disclosed
  • 2026-08-25: other: Published to NVD

References