CVE-2019-6342: Drupal

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

Affected products

  • Drupal Drupal: version 8.7.4 only

Published 2020-05-28. Last modified 2026-06-17.