A security flaw has been found in the Drupal Colorbox Inline module, which could allow attackers to inject malicious code into web pages. This type of vulnerability, known as Cross-Site Scripting (XSS), means that if you are using an affected version, your website could be at risk. This issue has been identified as a medium-severity threat.
CVE Details
This vulnerability affects the Drupal Colorbox Inline module.
- Published: May 19, 2026
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability specifically impacts the Colorbox Inline module for Drupal.
- Colorbox Inline versions from 0.0.0 up to, but not including, 2.1.1 are affected.
Current Status
The vulnerability (CVE-2026-8493) has been officially analyzed. This means security experts have reviewed and confirmed its details, making it important for users of the affected software to take action.
Severity Level
Rated as Medium severity with a CVSS score of 5.4, this Cross-Site Scripting (XSS) vulnerability can be exploited to perform actions like stealing user session cookies, redirecting users to malicious sites, or defacing web content. While not critical, it presents a significant risk to the integrity and security of websites using the module.
Possible Solutions
To protect your Drupal website, it is crucial to update the Colorbox Inline module. Users should upgrade to version 2.1.1 or later as soon as possible. Updating to the latest secure version will patch this Cross-Site Scripting vulnerability and help safeguard your site from potential attacks. Always ensure your modules are kept up-to-date.
References
https://www.drupal.org/sa-contrib-2026-036


