CVE-2026-10768
CRITICAL 9.8 PoC AVAILABLE ALL-YEARSMissing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
EXPLOIT AVAILABLE
Public exploit or PoC code exists. The barrier to attack is reduced — watch closely.
Exploitation likelihood
1.3%chance of exploitation in 30 days · 67th percentile
○ In CISA KEV● Public exploit / PoC◆ SSVC: exploitation none, automatable yes
Impact if exploited
9.8CVSS 3.1 · CRITICAL · ADP
- ConfidentialityHigh
- IntegrityHigh
- AvailabilityHigh
What an attacker needs
- ✓Access: Reachable over the network — no local access needed
- ✓Privileges: No account or privileges required
- ✓User interaction: No user interaction needed
- ✓Complexity: No special conditions — reliably repeatable
✓ lowers the bar for an attacker · ⚠ raises it
Proof of concept & exploit code
- nuclei https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-10768.yaml
- github-search https://github.com/search?q=%22CVE-2026-10768%22&type=repositories
Test against your own equipment
nuclei -id CVE-2026-10768 -u https://TARGETDetection template — non-destructive check that a target is affected.curl -s https://vulnpedia.com/cve/CVE-2026-10768/poc.jsonMachine-readable PoC index for this CVE (for automation).For defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-10768/poc.json
Weakness (CWE)
- CWE-862: Missing Authorization
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Known Affected Software Configurations
| Vendor | Product | Version range |
|---|---|---|
| Localgovdrupal | Localgov Workflows | < 1.6.0 |
All CVSS metrics
- CRITICAL 9.8 v3.1 · ADP Primary
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CRITICAL 9.8 v3.1 · NVD Secondary
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H