Junglewise Threat Intelligence

CVE-2026-84912: Drupal AI module access bypass in translation

CVE-2026-84912 · Severity: info · Published 2026-09-02

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Ai. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The AI Translate submodule for Drupal, which automatically translates website content entities, fails to properly verify user permissions on entities, fields, and related items being translated. This allows users with limited translation rights to translate entities and fields they shouldn't have access to, though the bypass is limited to translation operations only—attackers cannot read or modify the actual content.

Technical details

The AI Translate submodule performs insufficient access control checks during entity translation operations when the entity, related fields, or referenced entities have different access levels than the parent entity. This permission bypass is scoped to the translate operation and does not grant read or update access to restricted entities. The vulnerability affects Drupal/AI module versions before 1.3.13 and 1.4.0 through 1.4.7.

Affected products

  • Drupal AI <1.3.13 or >=1.4.0 <1.4.8

Timeline

  • 2026-09-02: disclosed

References

Related threats