Back

CVE-2017-6925

CRITICAL

In versions of Drupal 8 core prior to 8.3.7; There is a vulnerability in the entity access system that could allow unwanted access to view, create, update, or delete entities. This only affects entities that do not use or do not have UUIDs, and entities that have different access restrictions on different revisions of the same entity.

Published: Jan 15, 2019 Modified: Jun 17, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
drupal drupal * ≥ 8.0.0 < 8.3.7

GitHub Security Advisory GHSA-f4qx-jqfq-7785

Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions

composer drupal/core >= 8.0, < 8.3.7 Fixed: 8.3.7
composer drupal/drupal >= 8.0, < 8.3.7 Fixed: 8.3.7

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 3.02%

Top 14% most likely to be exploited

Threat Score 40.1 / 100

Data Sources

NVD EPSS GitHub