DIRAS TAKE
Treat this as high urgency: the flaw permits bypass without any login and a vendor fix (1.8.0) is available, so prioritize upgrades or immediate exposure restrictions.
What is CVE-2026-16639?
An unauthenticated attacker can bypass authentication in the Internationalization Single Sign-On module, allowing access as an authenticated user or full compromise of affected Drupal sites. CVE-2026-16639 affects the 1.x branch of the module, versions before 1.8.0; the vulnerability is exploitable over the network without credentials or user interaction. Administrators should assume internet-accessible or otherwise reachable installations are at risk until fixed. The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Drupal Internationalization Single Sign-On are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | before 1.8.0 | 1.8.0 |
Is CVE-2026-16639 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-16639
- Upgrade Internationalization Single Sign-On on affected sites to version 1.8.0.
- If immediate patching is not possible, restrict access to the module endpoints to trusted networks or block access at the firewall.
- Monitor authentication and access logs for anomalous logins or unexpected privilege escalations.
- Follow Drupal module maintainers' guidance and apply any additional vendor-recommended mitigations.
Frequently asked questions
Is CVE-2026-16639 being actively exploited?
There are no public reports of exploitation of CVE-2026-16639 as of 2026-09-29.
Which Internationalization Single Sign-On versions are affected by CVE-2026-16639?
The vulnerability affects the Internationalization Single Sign-On 1.x branch in versions before 1.8.0.
Is there a patch for CVE-2026-16639?
Yes. The issue is fixed in Internationalization Single Sign-On version 1.8.0; upgrade to that release.
Does CVE-2026-16639 require authentication?
No. The issue allows authentication bypass without valid credentials or user interaction against the Internationalization Single Sign-On module.
References
- nvd.nist.gov/vuln/detail/CVE-2026-16639
- cve.org/CVERecord?id=CVE-2026-16639
- drupal.org/sa-contrib-2026-081
- All Drupal CVEs on CVE Radar
- CVEs published in September 2026