{"id":"CVE-2016-3169","aliases":["GHSA-q3p9-8728-wq7x"],"url":"https://o3.security/vulnerability/CVE-2016-3169","summary":"Drupal saving user accounts can sometimes grant the user all roles","details":"The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.","published":"2016-04-12T15:59:06.933Z","modified":"2026-07-08T05:49:08.218608323Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"6.38"},{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"7.43"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"7.43"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"6.38"}],"fix":null,"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/02/24/19"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/03/15/10"},{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3498"},{"type":"FIX","url":"https://www.drupal.org/SA-CORE-2016-001"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:49:08.218608323Z"}}