CVE-2020-13677: Drupal

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.

Affected products

  • Drupal Drupal: from 8.0.0, before 8.9.19 (fixed in 8.9.19); from 9.1.0, before 9.1.13 (fixed in 9.1.13); from 9.2.0, before 9.2.6 (fixed in 9.2.6)

Published 2022-02-11. Last modified 2026-06-17.