CVE-2026-16639

Drupal · Internationalization Single Sign-On

An authentication bypass vulnerability in the Drupal Internationalization Single Sign-On module allows unauthenticated attackers to circumvent security controls.

Executive summary

The Internationalization Single Sign-On module for Drupal contains a critical authentication bypass flaw that permits unauthenticated remote attackers to gain full access to the system.

Vulnerability

The module suffers from an Authentication Bypass Using an Alternate Path or Channel (CWE-288), which allows an unauthenticated user to access the application without valid credentials.

Business impact

This vulnerability carries a CVSS score of 9.8, indicating a critical risk to organizational security. Successful exploitation grants an attacker full control over the affected Drupal site, potentially leading to total data compromise, unauthorized administrative actions, and significant reputational harm.

Remediation

Immediate Action: Review the official Drupal security advisory at the provided reference link to determine if a patch is available for your specific environment and apply it immediately. If no patch is available, disable the module until a secure version is released.

Proactive Monitoring: Inspect web server and application access logs for unusual traffic patterns or unauthorized requests that bypass standard login workflows.

Compensating Controls: Deploy or update Web Application Firewall (WAF) rules to detect and block common authentication bypass patterns targeting Drupal modules.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this authentication bypass, administrators must treat this vulnerability with the highest level of urgency. Immediately verify the version of the Internationalization Single Sign-On module currently in use and prioritize the implementation of the vendor-provided update or temporary module deactivation to prevent unauthorized access.

More Drupal CVEs

Sources

Originally found and disclosed by Drew Webber (mcdruid), with Florent Torregrosa (grimreaper) (remediation developer), Drew Webber (mcdruid) (remediation developer), Bram Driesen (bramdriesen) (coordinator), Greg Knaddison (greggles) (coordinator), Drew Webber (mcdruid) (coordinator), per the CVE Program record.