CVE-2016-7572: Drupal

Medium severity, CVSS 4.3. EPSS: 1.7% chance of exploitation in the next 30 days.

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

Affected products

  • Drupal Drupal: version 8.0.0 only; version 8.0.1 only; version 8.0.2 only; version 8.0.3 only; version 8.0.4 only; version 8.0.5 only; …

Published 2016-10-03. Last modified 2026-06-17.