CVE-2026-0748

In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" and "Administer content translations" permissions to view and attach unpublished nodes via the translation UI and its autocomplete widget. This bypasses intended access controls and discloses unpublished node titles and IDs. Exploit affects versions 7.x-1.0 up to and including 7.x-1.35.
Configurations

Configuration 1 (hide)

cpe:2.3:a:internationalization_project:internationalization:*:*:*:*:*:drupal:*:*

History

01 Apr 2026, 16:22

Type Values Removed Values Added
References () https://d7es.tag1.com/node/86 - () https://d7es.tag1.com/node/86 - Third Party Advisory
References () https://www.herodevs.com/vulnerability-directory/cve-2026-0748 - () https://www.herodevs.com/vulnerability-directory/cve-2026-0748 - Exploit, Third Party Advisory
References () https://www.herodevs.com/vulnerability-directory/cve-2026-0748?nes-for-drupal-7 - () https://www.herodevs.com/vulnerability-directory/cve-2026-0748?nes-for-drupal-7 - Exploit, Third Party Advisory
First Time Internationalization Project
Internationalization Project internationalization
CPE cpe:2.3:a:internationalization_project:internationalization:*:*:*:*:*:drupal:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE CWE-276

27 Mar 2026, 15:16

Type Values Removed Values Added
Summary
  • (es) En el módulo Internationalization (i18n) de Drupal 7, el submódulo i18n_node permite a un usuario con ambos permisos de 'Traducir contenido' y 'Administrar traducciones de contenido' ver y adjuntar nodos no publicados a través de la interfaz de usuario de traducción y su widget de autocompletado. Esto elude los controles de acceso previstos y revela los títulos e IDs de nodos no publicados. El exploit afecta a las versiones 7.x-1.0 hasta la 7.x-1.35 inclusive.
References
  • () https://www.herodevs.com/vulnerability-directory/cve-2026-0748?nes-for-drupal-7 -

26 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 22:16

Updated : 2026-04-01 16:22


NVD link : CVE-2026-0748

Mitre link : CVE-2026-0748

CVE.ORG link : CVE-2026-0748


JSON object : View

Products Affected

internationalization_project

  • internationalization
CWE
CWE-284

Improper Access Control

CWE-276

Incorrect Default Permissions