---
title: "CVE-2011-2726\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-2726?format=md
keywords: index, follow
---

# CVE-2011-2726

Publication date 15 November 2019

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2011-2726?format=md#impact-score)

Toggle side navigation

## Description

An access bypass issue was found in Drupal 7.x before version 7.5. If a
Drupal site has the ability to attach File upload fields to any entity type
in the system or has the ability to point individual File upload fields to
the private file directory in comments, and the parent node is denied
access, non-privileged users can still download the file attached to the
comment if they know or guess its direct URL.
If a Drupal site is using these features on comments, and the parent node is
denied access (either by a node access module or by being unpublished), the
file attached to the comment can still be downloaded by non-privileged users if
they know or guess its direct URL.
This issue affects Drupal 7.x only.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2011-2726?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| drupal7 | 11.10 oneiric | Not in release |
| 11.04 natty | Not in release |
| 10.10 maverick | Not in release |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [tyhicks](https://launchpad.net/~tyhicks)

7.x, before 7.5, affected

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2726)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-2726)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-2726)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-2726)

### Other references

* <http://www.openwall.com/lists/oss-security/2011/11/20/3>
* <https://www.cve.org/CVERecord?id=CVE-2011-2726>
