Drupal Facets Missing Authorization Vulnerability (CVE-2025-9549) — Medium Severity

A security concern has been identified within the Facets module for Drupal, revealing a vulnerability related to missing authorization. This issue could allow for what’s known as “forceful browsing,” potentially exposing sensitive information or functionality that should be restricted.

In simple terms, “missing authorization” means that the system isn’t properly checking if a user has the necessary permissions to access certain resources or perform specific actions. When this happens, an attacker might be able to bypass intended restrictions by directly navigating to specific URLs, a technique called “forceful browsing.” This could lead to unauthorized access to parts of your Drupal site that should remain private or protected.

CVE Details

The vulnerability is officially identified as CVE-2025-9549. It affects the Drupal Facets module. This issue was published on October 10, 2025, and is currently under an “Analyzed” status, indicating it has been thoroughly reviewed and understood by security researchers.

Affected Products

This missing authorization vulnerability impacts specific versions of the Drupal Facets module:

  • Facets module versions from 0.0.0 up to, but not including, 2.0.10
  • Facets module versions from 3.0.0 up to, but not including, 3.0.1

If you are running any of these affected versions, your Drupal installation could be at risk.

Current Status

As of its last modification on January 5, 2026, the status of CVE-2025-9549 is “Analyzed.” This means the vulnerability has been confirmed and details are available for users to understand and address the risk.

Severity Level

This vulnerability has been assigned a Medium severity rating, with a CVSS score of 6.5. A medium severity indicates that while the vulnerability is not immediately catastrophic, it still poses a significant risk to the confidentiality or integrity of your system. Attackers exploiting a missing authorization flaw could potentially gain access to information or perform actions they are not supposed to, which could lead to data exposure or unauthorized modifications on your Drupal site.

Possible Solutions

To secure your Drupal site against this missing authorization vulnerability, it is crucial to update your Facets module to a secure version. Based on the vulnerability details, users should:

  • Update Facets module installations in the 2.x branch to version 2.0.10 or later.
  • Update Facets module installations in the 3.x branch to version 3.0.1 or later.

Always ensure you back up your site before performing any updates, and test the updates in a development environment if possible, to prevent any unforeseen issues.

References

https://www.drupal.org/sa-contrib-2025-099

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.