
CVE-2026-3525 Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated): from 0.0.0 before… https://www.cve.org/CVERecord?id=CVE-2026-3525
Post summary
The text announces an incorrect authorization flaw in Drupal File Access Fix that permits forceful browsing, but does not include a PoC, exploit, patch or evidence of attack.
