CVE Database
/

CVE-2026-1554

Back to search

CVE-2026-1554

Published: Feb 4, 2026

Modified: Feb 5, 2026

PUBLISHED

Description

XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.

VendorProductVersions

Drupal

Central Authentication System (CAS) Server

affected
0.0.0 - < 2.0.3
affected
2.1.0 - < 2.1.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now