CVE-2026-1554

XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.
References
Link Resource
https://www.drupal.org/sa-contrib-2026-007 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jtenman:central_authentication_system_server:*:*:*:*:*:drupal:*:*
cpe:2.3:a:jtenman:central_authentication_system_server:*:*:*:*:*:drupal:*:*

History

17 Jun 2026, 10:16

Type Values Removed Values Added
Summary
  • (es) Inyección XML (también conocida como Inyección XPath Ciega) vulnerabilidad en el servidor del Sistema de Autenticación Central (CAS) de Drupal permite la escalada de privilegios. Este problema afecta al servidor del Sistema de Autenticación Central (CAS): desde 0.0.0 anterior a 2.0.3, desde 2.1.0 anterior a 2.1.2.

11 Feb 2026, 19:18

Type Values Removed Values Added
References () https://www.drupal.org/sa-contrib-2026-007 - () https://www.drupal.org/sa-contrib-2026-007 - Vendor Advisory
CPE cpe:2.3:a:jtenman:central_authentication_system_server:*:*:*:*:*:drupal:*:*
First Time Jtenman
Jtenman central Authentication System Server

05 Feb 2026, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.2

04 Feb 2026, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 21:15

Updated : 2026-06-17 10:16


NVD link : CVE-2026-1554

Mitre link : CVE-2026-1554

CVE.ORG link : CVE-2026-1554


JSON object : View

Products Affected

jtenman

  • central_authentication_system_server
CWE
CWE-91

XML Injection (aka Blind XPath Injection)