S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-10768 Scanner

CVE-2026-10768 Scanner - Information Disclosure vulnerability in Drupal LocalGov Workflows

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-10768
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LocalGov Workflowsby Drupal
AFFECTED< 1.6.0SAFE ✓≥ 1.6.0
Updated Aug 22, 2026View on NVD →
Detail

Drupal LocalGov Workflows is a module for the Drupal content management system, designed to enhance functionality for local government websites. It is used by government websites to manage and streamline content creation and publication processes. The module integrates with existing Drupal setups to provide workflow capabilities tailored for public sector organizations. Its primary users include developers and content managers working on municipal websites. The software aims to facilitate efficient content management and workflow automation within the government sector. It serves as a bridge between Drupal's core functionalities and the specific requirements of local government operations.

The vulnerability in this Drupal module is related to Information Disclosure, specifically due to a lack of proper access control measures. Attackers can take advantage of this by browsing to locations that should be protected but are exposed due to missing authorization checks. Without needing special privileges, unauthorized users might access sensitive information or functionalities. This vulnerability was identified in versions prior to 1.6.0 of the LocalGov Workflows module. It may provide attackers means to gather information or perform actions that should be restricted. Information Disclosure remains a critical issue because sensitive data and functional controls can be leaked, leading to potential data privacy violations.

The Information Disclosure vulnerability specifically affects endpoints that fail to check user privileges, allowing unauthorized browsing to potentially sensitive resources. The endpoint '/admin/content/localgov-service-contact/content-by-owner' exemplifies a location vulnerable to unauthorized access. Attackers might use this flaw to exploit parameters and retrieve data meant for administrators or specific users. The vulnerability's technical root lies in poor access control checks, exposing title, user, and status fields. An HTTP 200 status indicates a successful breach. This flaw underscores the importance of integrating comprehensive authorization checks in web applications.

If exploited, Information Disclosure in the LocalGov Workflows module could lead to the exposure of sensitive governmental or user data to unauthorized parties. Sensitive information could fall into malicious hands, risking user privacy or confidential governmental operations. This exposure might also give attackers insights into the system's structure or content handling processes, facilitating further attacks. Trust in the affected website could diminish as visitors learn of potential data mishandling. The exposure of content meant to remain confidential could have legal or compliance repercussions for the organizations impacted. Remediation and recovery efforts might be costly and resource-intensive.

REFERENCES

Solution Advice
  • Update the LocalGov Workflows module to a version later than 1.6.0.
  • Implement stringent access control measures to prevent unauthorized resource access.
  • Conduct regular audits of Drupal modules for known vulnerabilities.
  • Utilize security plugins or modules that reinforce access restrictions.
  • Educate users on best practices for managing sensitive information on collaborative platforms.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.