Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-10768: Drupal LocalGov Workflows Missing Authorization

CVE-2026-10768 CVE-2026-10768
Summary

A security issue in Drupal LocalGov Workflows allows unauthorized access to certain features. This affects versions 0.0.0 to 1.6.0 of the software. To stay secure, update to a fixed version of LocalGov Workflows as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
drupal localgov workflows < 1.6.0
Original title
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
Original description
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
Vulnerability type
CWE-862 Missing Authorization
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 10 Jul 2026