Medium severity4.2NVD Advisory· Published Jul 10, 2026· Updated Aug 6, 2026
CVE-2026-15083
CVE-2026-15083
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:jurgenhaas:eca\:_event_-_condition_-_action:*:*:*:*:*:drupal:*:*Range: <2.1.20
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2026-074nvdVendor Advisory
News mentions
1- Drupal: Ten Security Advisories Released Together on July 8, 2026Vypr Intelligence · Jul 8, 2026