Search api autocomplete: This module enables you to add autocomplete suggestions for search forms created with the Search API module. (CVE-2026-16640)
The Search API Autocomplete module for Drupal enables autocomplete suggestions for search forms created with the Search API module. A test script included with the module is accessible to anonymous users and does not sufficiently validate user input, resulting in a Cross Site Scripting (XSS) vulnerability. This vulnerability is mitigated by the requirement that the web server must be configured to display warning messages to users. Versions of the module prior to 1.12.0 are affected.
AI Analysis
Technical Summary
The Drupal Search API Autocomplete module contains a Cross Site Scripting vulnerability due to insufficient input validation in a test script accessible to anonymous users. This flaw allows injection of malicious scripts in the autocomplete suggestions feature. The vulnerability affects all versions before 1.12.0. Mitigation depends on web server configuration to display warning messages, reducing the risk of exploitation. No official patch or fix information is provided in the data.
Potential Impact
The vulnerability allows an attacker to perform Cross Site Scripting attacks via the test script in the module, potentially leading to script execution in the context of users accessing the vulnerable autocomplete feature. However, the impact is mitigated by the need for the web server to be configured to display warning messages, which limits exploitation. There are no known exploits in the wild reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. In the meantime, ensure the web server is configured to display warning messages to users as this mitigates the vulnerability. Avoid exposing the test script to anonymous users or restrict access to it until a fix is available.
Search api autocomplete: This module enables you to add autocomplete suggestions for search forms created with the Search API module. (CVE-2026-16640)
Description
The Search API Autocomplete module for Drupal enables autocomplete suggestions for search forms created with the Search API module. A test script included with the module is accessible to anonymous users and does not sufficiently validate user input, resulting in a Cross Site Scripting (XSS) vulnerability. This vulnerability is mitigated by the requirement that the web server must be configured to display warning messages to users. Versions of the module prior to 1.12.0 are affected.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Drupal Search API Autocomplete module contains a Cross Site Scripting vulnerability due to insufficient input validation in a test script accessible to anonymous users. This flaw allows injection of malicious scripts in the autocomplete suggestions feature. The vulnerability affects all versions before 1.12.0. Mitigation depends on web server configuration to display warning messages, reducing the risk of exploitation. No official patch or fix information is provided in the data.
Potential Impact
The vulnerability allows an attacker to perform Cross Site Scripting attacks via the test script in the module, potentially leading to script execution in the context of users accessing the vulnerable autocomplete feature. However, the impact is mitigated by the need for the web server to be configured to display warning messages, which limits exploitation. There are no known exploits in the wild reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. In the meantime, ensure the web server is configured to display warning messages to users as this mitigates the vulnerability. Avoid exposing the test script to anonymous users or restrict access to it until a fix is available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- DRUPAL-CONTRIB-2026-082
- Osv Schema Version
- 1.7.0
- Aliases
- ["CVE-2026-16640"]
- Ecosystems
- ["Packagist:https://packages.drupal.org/8"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a6151339c2644c7f8da7531
Added to database: 07/22/2026, 23:24:35 UTC
Last enriched: 07/23/2026, 00:10:59 UTC
Last updated: 07/23/2026, 00:25:17 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.