CVE-2026-73477: Quick Tabs Project Quick Tabs
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.
Affected products
- Quick Tabs Project Quick Tabs: from 4.0.0, before 4.3.1 (fixed in 4.3.1); from 5.x-1.0, up to and including 8.x-3.0
Published 2026-09-02. Last modified 2026-09-16.