Drupal Security
File Access Fix (deprecated) - Moderately critical - Access bypass - SA-CONTRIB-2026-020
Project: File Access Fix (deprecated)Date: 2026-March-04Security risk: Moderately critical 11 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <1.2.0CVE IDs: CVE-2026-3525Description:
This module moves files to and from private storage depending on the access of its owning entities.
The module does not sufficiently incorporate the results of hook_file_download when a custom or contrib module implements that hook leading to access bypass.
Install the latest version:
- If you use the File access fix module, upgrade to File access fix 8.x-1.2
- Pierre Rudloff (prudloff) provisional member of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Neue Kommentare
vor 1 Woche 4 Tagen
vor 1 Woche 6 Tagen
vor 1 Woche 6 Tagen
vor 2 Wochen 2 Tagen
vor 5 Wochen 4 Tagen
vor 5 Wochen 3 Tagen
vor 5 Wochen 3 Tagen
vor 6 Wochen 6 Tagen
vor 7 Wochen 1 Tag
vor 7 Wochen 3 Tagen