CVE-2016-7570: Drupal

Medium severity, CVSS 4.3. EPSS: 1.7% chance of exploitation in the next 30 days.

Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.

Affected products

  • Drupal Drupal: version 8.0.0 only; version 8.0.1 only; version 8.0.2 only; version 8.0.3 only; version 8.0.4 only; version 8.0.5 only; …

Published 2016-10-03. Last modified 2026-06-17.