CVE-2026-13244
8.1Drupal · Tealium iQ Tag Management
An improperly controlled modification of dynamically determined object attributes vulnerability in Drupal Tealium iQ Tag Management allows object injection.
Executive summary
An object injection vulnerability in Drupal Tealium iQ Tag Management allows authenticated attackers to compromise data confidentiality and integrity.
Vulnerability
This flaw involves improper control of dynamically determined object attributes, leading to object injection via the network vector. The attack requires low privileges and no user interaction.
Business impact
A successful exploitation of this vulnerability permits unauthorized actors to manipulate internal object attributes, leading to a high impact on data confidentiality and integrity. Given the CVSS score of 8.1, the business risk is substantial, potentially resulting in unauthorized data modification, sensitive data exposure, or privilege escalation within the content management framework.
Remediation
Immediate Action: Update Drupal Tealium iQ Tag Management to version 2.4.0 or later as detailed in the vendor advisory.
Proactive Monitoring: Review web server and application access logs for unusual requests directed at module endpoints, particularly those originating from accounts with low privilege levels.
Compensating Controls: Deploy Web Application Firewall rules to detect and block suspicious object serialization payloads or parameter tampering patterns targeting Drupal contributed modules.
Exploitation status
Public Exploit Available: No (false)
Analyst recommendation
Administrators must treat this high-severity vulnerability with urgency by reviewing installed contributed modules and applying the official vendor patch as soon as possible. Restricting administrative and low-level module management permissions further minimizes exposure until updates are fully deployed across all environments.
More Drupal CVEs
Sources
Originally found and disclosed by Drew Webber (mcdruid), with Benji Fisher (benjifisher) (remediation developer), Daniel Schiavone (schiavone) (remediation developer), Benji Fisher (benjifisher) (coordinator), Bram Driesen (bramdriesen) (coordinator), Neil Drumm (drumm) (coordinator), per the CVE Program record.