VYPR
High severityNVD Advisory· Published Oct 29, 2025· Updated Oct 30, 2025

Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-105

CVE-2025-9954

Description

Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.0.0 before 1.1.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Acquia DAM module for Drupal fails to properly validate authorization when listing synced assets, allowing unauthenticated users to bypass access controls and view restricted media.

Vulnerability

Overview

The Acquia DAM module for Drupal, which synchronizes media from the Acquia DAM service to a Drupal site, contains a missing authorization vulnerability [1]. The module does not sufficiently validate a user's authorization when listing DAM assets that have been synced to the website, leading to an access bypass issue [2]. This flaw affects all versions of the module before 1.1.5.

Exploitation

Details

The vulnerability can be exploited by any user who has the "view media" permission, even if they should not have access to specific DAM assets [2]. The attack vector is network-based, requires no privileges, and no user interaction, making it relatively easy to exploit [2]. The issue specifically impacts the views that list DAM assets, including the Acquia DAM Asset Library, Acquia DAM links, and DAM Content Overview views [2].

Impact

Successful exploitation allows an attacker to forcefully browse and access DAM assets that should be restricted, leading to unauthorized information disclosure [1][2]. The CVSS score for this vulnerability is 6.9 (Medium), with the primary impact being on confidentiality [2].

Mitigation

The vendor has released version 1.1.5 of the Acquia DAM module, which fixes the vulnerability by adding permission-based access control to the affected views [2]. Users are strongly advised to upgrade to this version. For sites that cannot immediately update, a workaround exists: manually modify the three affected views to restrict access to the "access media overview" permission [2].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
drupal/acquia_damPackagist
< 1.1.51.1.5

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.