PatchSiren

Diff Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Diff Project CVE published 2026-09-02

CVE-2026-73478

CVE-2026-73478 is an Incorrect Authorization vulnerability in Drupal Diff that allows Forceful Browsing. The issue affects Diff versions from 0.0.0 to 2.0.1 and from 2.1.0 to 2.1.1. According to the CVE Program and NVD, this vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Defenders should prioritize verifying exposure in their Drupal installations using the affected Diff versions and apply [truncated]