Junglewise Threat Intelligence

CVE-2026-16646: Drupal PanKM unsupported project security issue

CVE-2026-16646 · Severity: medium · CVSS 5.7 · Published 2026-08-25

Executive brief

PanKM is a Drupal distribution that bundles multiple modules for content management, surveys, user management, and media handling. The project has been marked as unsupported by the Drupal security team due to an unresolved security vulnerability that the maintainer has not addressed, leaving deployments exposed to known risks.

Technical details

PanKM is an unsupported Drupal 8 distribution that packages multiple modules including Taxonomy Import, Videos, Survey, Chart, User Management, and a security module. A security vulnerability (CVE-2026-16646) has been identified in the project but remains unfixed by the maintainer, resulting in the Drupal security team marking it as unsupported on 2026-07-22. The specific vulnerability class and technical root cause are not disclosed in available advisories, but the issue is considered critical enough to recommend complete uninstallation. No patch is available, and users must either uninstall the project, find an alternative maintained solution, or hire developers to fix the vulnerability themselves.

Affected products

  • PanApps PanKM all versions

Timeline

  • 2026-07-22: disclosed: Drupal security team marked project unsupported due to unfixed vulnerability
  • 2026-08-25: advisory: CVE-2026-16646 published

References