CVE-2024-55634: Drupal
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.
Affected products
- Drupal Drupal: from 8.0.0, before 10.2.11 (fixed in 10.2.11); from 10.3.0, before 10.3.9 (fixed in 10.3.9); from 11.0.0, before 11.0.8 (fixed in 11.0.8)
Published 2024-12-10. Last modified 2026-06-17.