Drupal Acquia Content Hub Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in Drupal Acquia Content Hub versions prior to 3.6.4 and from 3.7.0 prior to 3.7.3. The vulnerability allows an attacker to trick an admin into exporting an unwanted entity by exploiting insufficient protection on export routes.

Impact

Exploitation of this vulnerability could lead to unauthorized content exports, potentially allowing attackers to manipulate or disrupt content distribution processes.

Remediation

Users of Acquia Content Hub 3.6.x should upgrade to version 3.6.4. Users of Acquia Content Hub 3.7.x should upgrade to version 3.7.3. The latest version, 3.8.0, is also available and includes this security fix along with other improvements.

Added: Jan 28, 2026, 8:46 PM
Updated: Jan 28, 2026, 8:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
6.2
remediation
0.0
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.