Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

Drupal CMS: Unauthenticated File Upload Allows Remote Code Execution

MINI-8c2j-564f-3qgx
Summary

A flaw in the Drupal Content Management System allows an attacker to upload malicious files without permission, potentially allowing them to execute code on your website. This can lead to data theft, website takeover, or other malicious activities. Update your Drupal installation to the latest version to fix this issue.

What to do
  • Update openclaw to version 2026.3.7-r0.
Affected software
VendorProductAffected versionsFix available
– openclaw <= 2026.3.7-r0 2026.3.7-r0
Original title
MINI-8c2j-564f-3qgx
Published: 8 Mar 2026 · Updated: 13 Mar 2026 · First seen: 8 Mar 2026