Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.2

CVE-2026-15083: Drupal ECA: Event - Condition - Action allows Object Injection

CVE-2026-15083 CVE-2026-15083
Summary

A security flaw in Drupal's ECA module allows an attacker to inject malicious code, potentially giving them unauthorized access to sensitive data. This affects certain versions of the ECA module, which is used to create custom event handling rules. To stay secure, update the ECA module to the latest version or patch level.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
drupal eca: event - condition - action < 2.1.20
Original title
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condi...
Original description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4.
Vulnerability type
CWE-915
Published: 10 Jul 2026 · Updated: 14 Jul 2026 · First seen: 10 Jul 2026