Project: 
Project machine name: 
cloud
Date: 
2026-September-23
Vulnerability: 
Remote code execution
Affected versions: 
<7.0.1
CVE IDs: 
CVE-2026-96375
Description: 

The Cloud module enables users to manage cloud infrastructure through Drupal.

The Kubernetes and VMware integrations do not properly validate TLS certificates when connecting to remote API endpoints. An attacker who can intercept these connections may obtain secret tokens or other credentials, potentially allowing unauthorized access to the connected infrastructure.

Solution: 

If you use Cloud, install the latest version and configure certificates appropriately:

  • If you use the 7.0.0 branch, update to 7.0.1.

The update enables TLS certificate verification for Kubernetes and VMware connections. Sites using a private certificate authority must configure the CA certificate path for the affected connection or ensure that the issuing CA is trusted by the PHP runtime. Run the Drupal database updates and rebuild caches after upgrading.

Reported By: 
Coordinated By: