• PATCH AVAILABLE

CVE-2026-16639: authentication bypass in Drupal Internationalization Single Sign-On

An unauthenticated attacker can bypass authentication in the Internationalization Single Sign-On module, allowing access as an authenticated user or full compromise of affected Drupal sites. CVE-2026-16639 affects the 1.x branch of the module, versions before 1.8.0; the vulnerability is exploitable over the network without credentials or user interaction. Administrators should assume internet-accessible or otherwise reachable installations are at risk until fixed.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00366
CWE
CWE-288
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as high urgency: the flaw permits bypass without any login and a vendor fix (1.8.0) is available, so prioritize upgrades or immediate exposure restrictions.

What is CVE-2026-16639?

An unauthenticated attacker can bypass authentication in the Internationalization Single Sign-On module, allowing access as an authenticated user or full compromise of affected Drupal sites. CVE-2026-16639 affects the 1.x branch of the module, versions before 1.8.0; the vulnerability is exploitable over the network without credentials or user interaction. Administrators should assume internet-accessible or otherwise reachable installations are at risk until fixed. The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Drupal Internationalization Single Sign-On are affected?

BRANCHAFFECTEDFIXED
1.xbefore 1.8.01.8.0

Is CVE-2026-16639 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-16639

  1. Upgrade Internationalization Single Sign-On on affected sites to version 1.8.0.
  2. If immediate patching is not possible, restrict access to the module endpoints to trusted networks or block access at the firewall.
  3. Monitor authentication and access logs for anomalous logins or unexpected privilege escalations.
  4. Follow Drupal module maintainers' guidance and apply any additional vendor-recommended mitigations.

Frequently asked questions

Is CVE-2026-16639 being actively exploited?

There are no public reports of exploitation of CVE-2026-16639 as of 2026-09-29.

Which Internationalization Single Sign-On versions are affected by CVE-2026-16639?

The vulnerability affects the Internationalization Single Sign-On 1.x branch in versions before 1.8.0.

Is there a patch for CVE-2026-16639?

Yes. The issue is fixed in Internationalization Single Sign-On version 1.8.0; upgrade to that release.

Does CVE-2026-16639 require authentication?

No. The issue allows authentication bypass without valid credentials or user interaction against the Internationalization Single Sign-On module.

References