Newsfeed-Generator
AJAX Dashboard - Critical - Access bypass - SA-CONTRIB-2026-022
AJAX Dashboard: Entity Dashboards enables you to create configurable dashboards attached to entities which include AJAX-reloading of a main content area based on inputs from a configurable set of buttons.
The module doesn't sufficiently check access on the dashboard configuration route. Unauthorized users could access the entity dashboard configuration page and either enable or disable dashboards. The affected administration page does not permit editing the configurations of the dashboards themselves.
The vulnerability is mitigated by the fact that the AJAX Dashboard Entity Dashboard submodule must be enabled.
Solution:Install the latest version of the AJAX Dashboard module, which includes the update to AJAX Dashboard: Entity Dashboards:
- If you use the AJAX Dashboard module, upgrade to AJAX Dashboard 3.1.0
- Juraj Nemec (poker10) of the Drupal Security Team
- Bram Driesen (bramdriesen) provisional member of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-021
This module moves files to and from private storage depending on the access of its owning entities.
The module does not always validate the access logic correctly, resulting in files attached to an entity not being protected in certain circumstances.
This vulnerability is mitigated by the fact that saving an entity a second time resolves the issue.
Solution:Install the latest version:
- If you use the File access fix module, upgrade to File access fix 8.x-1.2
- Pierre Rudloff (prudloff) provisional member of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-020
This module moves files to and from private storage depending on the access of its owning entities.
The module does not sufficiently incorporate the results of hook_file_download when a custom or contrib module implements that hook leading to access bypass.
Install the latest version:
- If you use the File access fix module, upgrade to File access fix 8.x-1.2
- Pierre Rudloff (prudloff) provisional member of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team

Neue Kommentare
vor 1 Woche 3 Tagen
vor 1 Woche 5 Tagen
vor 1 Woche 5 Tagen
vor 2 Wochen 1 Tag
vor 5 Wochen 3 Tagen
vor 5 Wochen 2 Tagen
vor 5 Wochen 2 Tagen
vor 6 Wochen 5 Tagen
vor 7 Wochen 7 Stunden
vor 7 Wochen 2 Tagen