Junglewise Threat Intelligence

CVE-2026-96375: Drupal Cloud module TLS certificate validation bypass

CVE-2026-96375 · Severity: info · Published 2026-09-23

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Cloud module for Drupal allows administrators to manage cloud infrastructure including Kubernetes and VMware environments. The Kubernetes and VMware integrations fail to properly validate TLS certificates, allowing an attacker on the network to intercept connections and steal secret tokens or credentials that grant access to the connected cloud infrastructure.

Technical details

The Kubernetes and VMware integrations in the Cloud module do not validate TLS certificates when connecting to remote API endpoints, enabling man-in-the-middle attacks over network connections. An attacker who can intercept traffic between the Drupal server and the remote cloud infrastructure APIs can capture authentication tokens and credentials. The vulnerability is fixed in version 7.0.1, which enables TLS certificate verification and requires proper certificate authority configuration.

Affected products

  • Drupal Cloud before 7.0.1

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Version 7.0.1 released with TLS certificate validation enabled

References

Related threats