Drupal Acquia Content Hub Cross-Site Request Forgery Vulnerability (CVE-2025-14472) — High Severity

The Drupal Acquia Content Hub module has been found to contain a Cross-Site Request Forgery (CSRF) vulnerability, identified as CVE-2025-14472. This issue poses a high-severity risk to affected installations.

Cross-Site Request Forgery is a type of attack where a malicious website or email can trick a web browser into performing unwanted actions on a trusted site where the user is currently authenticated. Imagine logging into your bank website, then, without knowing, clicking a link in a separate tab that secretly tries to transfer money from your account using your existing login session. This vulnerability in Acquia Content Hub could allow an attacker to trick a logged-in administrator or user into performing actions they didn’t intend, potentially leading to unauthorized data manipulation or other malicious activities within the content hub.

CVE Details

This vulnerability affects the Acquia Content Hub module for Drupal.

Published: January 28, 2026

Severity: High (CVSS Score: 8.1)

Status: Analyzed

Affected Products

The following versions of the Acquia Content Hub module for Drupal are affected:

  • All versions from 0.0.0 up to, but not including, 3.6.4
  • All versions from 3.7.0 up to, but not including, 3.7.3

Current Status

This vulnerability has been analyzed and publicly disclosed. Organizations using the affected module versions should take immediate action to mitigate the risk.

Severity Level

The vulnerability has been assigned a CVSS score of 8.1, classifying it as a High severity issue. This indicates that the flaw could be exploited relatively easily and could have a significant impact on the confidentiality, integrity, or availability of your Drupal site’s content management. The potential for an attacker to force authenticated users to execute unintended actions underscores the seriousness of this security flaw.

Possible Solutions

To protect your Drupal site from this CSRF vulnerability, it is crucial to update your Acquia Content Hub module to a secure version. Based on the vulnerability details, the following versions are considered patched:

  • Acquia Content Hub version 3.6.4 and later
  • Acquia Content Hub version 3.7.3 and later

It is highly recommended that IT administrators and developers review their current Acquia Content Hub installations and upgrade to the latest secure release as soon as possible. Regular security audits and staying updated with security advisories for all modules and core Drupal installations are also vital practices for maintaining a robust security posture.

References

https://www.drupal.org/sa-contrib-2025-125

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.