CVE-2025-8361: Config Pages Project Config Pages

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing. This issue affects Config Pages: from 0.0.0 before 2.18.0.

Affected products

Published 2025-08-15. Last modified 2026-08-10.