CVE-2026-3525 | File Access Fix up to 1.1.x on Drupal authorization (sa-contrib-2026-020)
A vulnerability, which was classified as critical, has been found in File Access Fix up to 1.1.x on Drupal. The impacted element is an unknown function. This manipulation causes incorrect authorization.
This vulnerability is tracked as CVE-2026-3525. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.