CVE-2026-73478: Diff Project Diff

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.

Affected products

  • Diff Project Diff: before 2.0.1 (fixed in 2.0.1); from 5.x-1.0, up to and including 5.x-2.1; from 6.x-1.0, up to and including 6.x-2.3; from 7.x-3.0, up to and including 7.x-3.5; from 8.x-1.0, up to and including 8.x-1.10; version 2.1.0 only; …

Published 2026-09-02. Last modified 2026-09-16.