Intel

AIKIDO-2025-10495

drupal/panels is vulnerable to Authentication Bypass

Authentication BypassCVE-2025-3474 Published Jul 22, 2025

90

Critical Risk

This Affects:

PHPdrupal/panels
1.0.0 - 4.8.0
Fixed in 4.9.0
Are you affected? Scan for Free

TL;DR

The module doesn't sufficiently protect sensitive routes, allowing an attacker to view and modify blocks within variants without requiring appropriate permission.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/panels is vulnerable to Authentication Bypass in versions 1.0.0 - 4.8.0.

How to fix this

Upgrade the drupal/panels library to the patch version.