Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-105
Description
Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.0.0 before 1.1.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Acquia DAM module for Drupal fails to properly validate authorization when listing synced assets, allowing unauthenticated users to bypass access controls and view restricted media.
Vulnerability
Overview
The Acquia DAM module for Drupal, which synchronizes media from the Acquia DAM service to a Drupal site, contains a missing authorization vulnerability [1]. The module does not sufficiently validate a user's authorization when listing DAM assets that have been synced to the website, leading to an access bypass issue [2]. This flaw affects all versions of the module before 1.1.5.
Exploitation
Details
The vulnerability can be exploited by any user who has the "view media" permission, even if they should not have access to specific DAM assets [2]. The attack vector is network-based, requires no privileges, and no user interaction, making it relatively easy to exploit [2]. The issue specifically impacts the views that list DAM assets, including the Acquia DAM Asset Library, Acquia DAM links, and DAM Content Overview views [2].
Impact
Successful exploitation allows an attacker to forcefully browse and access DAM assets that should be restricted, leading to unauthorized information disclosure [1][2]. The CVSS score for this vulnerability is 6.9 (Medium), with the primary impact being on confidentiality [2].
Mitigation
The vendor has released version 1.1.5 of the Acquia DAM module, which fixes the vulnerability by adding permission-based access control to the affected views [2]. Users are strongly advised to upgrade to this version. For sites that cannot immediately update, a workaround exists: manually modify the three affected views to restrict access to the "access media overview" permission [2].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
drupal/acquia_damPackagist | < 1.1.5 | 1.1.5 |
Affected products
2- Range: <1.1.5
- Drupal/Acquia DAMv5Range: 0.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-x957-32v9-m7vgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-9954ghsaADVISORY
- www.drupal.org/sa-contrib-2025-105ghsaWEB
News mentions
0No linked articles in our index yet.