The Drupal Acquia Content Hub module has been found to contain a Cross-Site Request Forgery (CSRF) vulnerability, identified as CVE-2025-14472. This issue poses a high-severity risk to affected installations.
Cross-Site Request Forgery is a type of attack where a malicious website or email can trick a web browser into performing unwanted actions on a trusted site where the user is currently authenticated. Imagine logging into your bank website, then, without knowing, clicking a link in a separate tab that secretly tries to transfer money from your account using your existing login session. This vulnerability in Acquia Content Hub could allow an attacker to trick a logged-in administrator or user into performing actions they didn’t intend, potentially leading to unauthorized data manipulation or other malicious activities within the content hub.
CVE Details
This vulnerability affects the Acquia Content Hub module for Drupal.
Published: January 28, 2026
Severity: High (CVSS Score: 8.1)
Status: Analyzed
Affected Products
The following versions of the Acquia Content Hub module for Drupal are affected:
- All versions from 0.0.0 up to, but not including, 3.6.4
- All versions from 3.7.0 up to, but not including, 3.7.3
Current Status
This vulnerability has been analyzed and publicly disclosed. Organizations using the affected module versions should take immediate action to mitigate the risk.
Severity Level
The vulnerability has been assigned a CVSS score of 8.1, classifying it as a High severity issue. This indicates that the flaw could be exploited relatively easily and could have a significant impact on the confidentiality, integrity, or availability of your Drupal site’s content management. The potential for an attacker to force authenticated users to execute unintended actions underscores the seriousness of this security flaw.
Possible Solutions
To protect your Drupal site from this CSRF vulnerability, it is crucial to update your Acquia Content Hub module to a secure version. Based on the vulnerability details, the following versions are considered patched:
- Acquia Content Hub version 3.6.4 and later
- Acquia Content Hub version 3.7.3 and later
It is highly recommended that IT administrators and developers review their current Acquia Content Hub installations and upgrade to the latest secure release as soon as possible. Regular security audits and staying updated with security advisories for all modules and core Drupal installations are also vital practices for maintaining a robust security posture.
References
https://www.drupal.org/sa-contrib-2025-125


