Startseite
  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche
Startseite › Newsfeed-Generator › Herkunft ›

Drupal Contrib Security

Inhalt abgleichen
URL: https://www.drupal.org/security/contrib
Aktualisiert: vor 47 Minuten 48 Sekunden

Media Library Importer - Moderately critical - Access bypass - SA-CONTRIB-2026-129

2 September, 2026 - 18:35
Project: Media Library ImporterProject machine name: media_library_importerDate: 2026-September-02Security risk: Moderately critical 11 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <2.1.6CVE IDs: CVE-2026-81163Description: 

A module to import media files into media library.

The import folder is a plain textfield with no validation. Point it at any directory the web user can read, and the importer copies every file whose extension matches a selected media type into the public files directory and publishes it as a Media entity. Files that were deliberately kept outside the webroot, such as a private file store, become downloadable by anonymous visitors at a predictable URL.

Solution: 

Install the latest version:

  • If you use the Media Library Importer module for Drupal upgrade to Media Library Importer 2.1.6
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Italo Mairo (itamair)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Mailer Plus Log - Moderately critical - Access bypass - SA-CONTRIB-2026-128

2 September, 2026 - 18:34
Project: Mailer Plus LogProject machine name: symfony_mailer_logDate: 2026-September-02Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: <1.2.7CVE IDs: CVE-2026-16648Description: 

This module enables you to log the emails sent by Mailer Plus as content entities, so they can be reviewed at Reports > Mail log.

The module doesn't sufficiently redact the content of the emails it logs. Account related emails are stored with their one-time login links intact, so any user who can view the log can obtain a one-time login link for any account, including user 1, and use it to log in as that account.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission View Drupal Symfony Mailer log entries, which in earlier releases was not marked as a restricted permission.

Solution: 

Install the latest version:

  • If you use the Mailer Plus Log module (previously known as Symfony Mailer Log), upgrade to Mailer Plus Log 1.2.7
  • After updating, run database updates so that the email bodies already stored in the log are redacted.
  • Review who should have the View Drupal Symfony Mailer log entries permission, and whether your site sends out custom sensitive emails that would need to opt in to the redaction logic.
Reported By: 
  • Sven Decabooter (svendecabooter)
Fixed By: 
  • Mohit Aghera (mohit_aghera) provisional member of the Drupal Security Team
  • Sven Decabooter (svendecabooter)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Mohit Aghera (mohit_aghera)
Kategorien: Drupal Security

Jsonapi Role Access - Critical - Access bypass - SA-CONTRIB-2026-127

2 September, 2026 - 18:33
Project: Jsonapi Role Access Project machine name: jsonapi_role_accessDate: 2026-September-02Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <2.0.2CVE IDs: CVE-2026-84917Description: 

This module enables you to restrict access to JSON:API routes based on specific user roles.

The module doesn't sufficiently enforce access controls under scenarios where a request mimics an XMLHttpRequest.

Solution: 

Install the latest version:

  • If you use the Jsonapi Role Access module, upgrade to Jsonapi Role Access 2.0.2
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Julian Pustkuchen (anybody)
  • Joshua Sedler (grevil)
Coordinated By: 
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Islandora - Moderately critical - Access bypass - SA-CONTRIB-2026-126

2 September, 2026 - 18:32
Project: Islandora Project machine name: islandoraDate: 2026-September-02Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <2.19.0CVE IDs: CVE-2026-84916Description: 

This islandora_advanced_search sub module enables AJAX updates for advanced search, facet, and search result blocks.

The module doesn't sufficiently check block access when arbitrary block ID's are submitted to its publicly accessible AJAX endpoint. This may allow an unauthenticated attacker to retrieve restricted block content.

This vulnerability is mitigated by the fact that an attacker must know or guess a restricted block’s machine ID, and the block must contain sensitive content protected by block access or visibility restrictions. Additionally, the submodule is not known to be used by any modern Islandora configurations.

Solution: 

Install the latest version:

  • If you use the Islandora module, upgrade to the latest version Islandora 2.19.0. Be sure to read the release node for advice on updating
Reported By: 
  • Joe Corall (joecorall)
Fixed By: 
  • Annie Oelschlager (annieoelschlager)
  • Joe Corall (joecorall)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Email Verification / SMS Verification / OTP Verification - Critical - Cross Site Scripting - SA-CONTRIB-2026-125

2 September, 2026 - 18:31
Project: Email Verification / SMS Verification / OTP VerificationProject machine name: otp_verificationDate: 2026-September-02Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross Site ScriptingAffected versions: <2.4.0CVE IDs: CVE-2026-84924Description: 

This module enables you to add an extra layer of verification for user registration.

The module doesn't sufficiently filter user-supplied input before output, resulting in an unauthenticated reflected Cross-site Scripting (XSS) vulnerability.

Solution: 

Install the latest version:

If you are using the OTP Verification module for Drupal, upgrade to the latest version 8.x-2.4

Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Mohammed Hisam (hisam45)
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Email Verification / SMS Verification / OTP Verification - Critical - Access Bypass - SA-CONTRIB-2026-124

2 September, 2026 - 18:30
Project: Email Verification / SMS Verification / OTP VerificationProject machine name: otp_verificationDate: 2026-September-02Security risk: Critical 16 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Access BypassAffected versions: <2.4.0CVE IDs: CVE-2026-84923Description: 

This module enables you to add extra layer of verification for user registration.

The module doesn't sufficiently validate user-supplied input resulting in an account takeover vulnerability.

Solution: 

Install the latest version:

If you are using the OTP Verification module for Drupal, upgrade to latest version 8.x-2.4

Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Mohammed Hisam (hisam45)
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Component blocks - Moderately critical - Cross site scripting - SA-CONTRIB-2026-123

2 September, 2026 - 18:29
Project: Component blocksProject machine name: component_blocksDate: 2026-September-02Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:AllVulnerability: Cross site scriptingAffected versions: <1.2.7CVE IDs: CVE-2026-84915Description: 

This module enables you use UI Patterns with blocks, for use in Layout Builder.

The module doesn't sufficiently validate user input before passing to token replacement.

This vulnerability is mitigated by the fact that an attacker must have a role with the ability to edit layout builder layouts.

Solution: 

Install the latest version:

  • If you use the component_blocks module, upgrade to Component Blocks 1.2.7
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
Kategorien: Drupal Security

Calculate Working Days - Critical - Access bypass - SA-CONTRIB-2026-122

2 September, 2026 - 18:29
Project: Calculate Working DaysProject machine name: calculate_working_daysDate: 2026-September-02Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:None/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <2.0.3CVE IDs: CVE-2026-84914Description: 

Calculate Working Days allows you to calculate working days
between 2 dates.

This module doesn't sufficiently restrict access to its settings form.

Solution: 

Install the latest version:

  • If you use the Calculate Working Days module, upgrade to calculate_working_days 2.0.3
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Vivek kumar (vivek_lnwebworks)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

AI translate - Moderately critical - Access Bypass - SA-CONTRIB-2026-121

2 September, 2026 - 18:28
Project: AI translateProject machine name: ai_translateDate: 2026-September-02Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access BypassAffected versions: <1.3.2 || >=1.4.0 <1.4.1CVE IDs: CVE-2026-84913Description: 

This module enables you to automatically translate entities.

The module doesn't sufficiently check access on the entity to be translated, related fields or referenced entities when performing an AI translation on an entity or when those fields / entities have a different access level than the parent entity. This permission bypass is only applicable to the translate operation - no unwarranted read or update access is granted to the affected entities

Solution: 

Install the latest version:

  • If you use AI Translate 1.3.x, upgrade to AI Translate 1.3.2
  • If you use AI Translate 1.4.x, upgrade to AI Translate 1.4.1
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Artem Dmitriiev (a.dmitriiev)
  • Marcus Johansson (marcus_johansson)
  • Sven Decabooter (svendecabooter)
  • Valery Lourie (valthebald)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

AI (Artificial Intelligence) - Moderately critical - Access Bypass - SA-CONTRIB-2026-120

2 September, 2026 - 18:27
Project: AI (Artificial Intelligence)Project machine name: aiDate: 2026-September-02Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access BypassAffected versions: <1.3.13 || >=1.4.0 <1.4.8CVE IDs: CVE-2026-84912Description: 

This submodule AI Translate enables you to automatically translate entities.

The module doesn't sufficiently check access on the entity to be translated, related fields or referenced entities when performing an AI translation on an entity or when those fields / entities have a different access level than the parent entity. This permission bypass is only applicable to the translate operation - no unwarranted read or update access is granted to the affected entities

Solution: 

Install the latest version:

  • If you use the AI module 1.4.7 or below upgrade to AI module 1.4.8
  • If you use the AI module 1.3.12 or below upgrade to AI module 1.3.13
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Artem Dmitriiev (a.dmitriiev)
  • Marcus Johansson (marcus_johansson)
  • Sven Decabooter (svendecabooter)
  • Valery Lourie (valthebald)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

AI (Artificial Intelligence) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-119

2 September, 2026 - 18:26
Project: AI (Artificial Intelligence)Project machine name: aiDate: 2026-September-02Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross site scriptingAffected versions: <1.3.13 || >=1.4.0 <1.4.8CVE IDs: CVE-2026-84911Description: 

This AI Chatbot module enables you to have a Chatbot using assistants to help you with your Drupal website.

The module doesn't sufficiently sanitize for cross site scripting (XSS) when using the structured results using legacy agent setups.

This vulnerability is mitigated by the fact that an attacker must be able to invoke a prompt injection set via editorial content and the site must have been setup using AI 1.0.x and AI Agents 1.0.x branch using a uncommon configuration. Any configuration setup or updated after these minor versions are not affected.

Solution: 

Install the latest version:

  • If you use the AI module 1.4.7 or below upgrade to AI module 1.4.8
  • If you use the AI module 1.3.12 or below upgrade to AI module 1.3.13
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Artem Dmitriiev (a.dmitriiev)
  • Marcus Johansson (marcus_johansson)
  • Valery Lourie (valthebald)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
Kategorien: Drupal Security

Advanced Search - Moderately critical - Access bypass - SA-CONTRIB-2026-118

2 September, 2026 - 18:25
Project: Advanced SearchProject machine name: advanced_searchDate: 2026-September-02Security risk: Moderately critical 12 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <2.4.5CVE IDs: CVE-2026-84910Description: 

This module enables AJAX updates for advanced search, facet, and search result blocks.

The module doesn’t sufficiently check block access when arbitrary block IDs are submitted to its publicly accessible AJAX endpoint. This may allow an unauthenticated attacker to retrieve restricted block content.

This vulnerability is mitigated by the fact that an attacker must know or guess a restricted block’s machine ID, and the block must contain sensitive content protected by block access or visibility restrictions.

Solution: 

Install the latest version:

  • If you use the Advanced Search module, upgrade to Advanced Search 2.4.5
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Annie Oelschlager (annieoelschlager)
  • Joe Corall (joecorall)
  • Marcus Johansson (marcus_johansson)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117

26 August, 2026 - 19:45
Project: Slick CarouselProject machine name: slickDate: 2026-August-26Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross Site ScriptingAffected versions: <2.1.0CVE IDs: CVE-2026-81160Description: 

Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons.

Previous releases of the module did not sufficiently validate user input, leading to a Cross Site Scripting (XSS) vulnerability.

Note: This vulnerability was fixed in 8.x-2.1 but that was not marked as a security release at the time.

Solution: 
  • Only the 3.0.x branch is supported by the maintainers. Upgrade to a release on that branch.
Reported By: 
  • Drew Webber (mcdruid) of the Drupal Security Team
Fixed By: 
  • Gaus Surahman (gausarts)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • cilefen of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Kategorien: Drupal Security

Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116

26 August, 2026 - 19:44
Project: Monster MenusProject machine name: monster_menusDate: 2026-August-26Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site ScriptingAffected versions: <9.5.3CVE IDs: CVE-2026-81201Description: 

This module enables you to create one or more multisites with highly granular page permissions.

The module doesn't sufficiently sanitize HTML code contained in the page name when displayed in the built-in tree browser. This results in a cross-site scripting vulnerability that may allow attackers to execute arbitrary JavaScript in the context of the user’s session.

This vulnerability is mitigated by the fact that an attacker must have the ability to create pages whose page title supports HTML.

Solution: 

Install the latest version:

  • If you use the Monster Menus module, upgrade to monster_menus 9.5.3.
Reported By: 
  • Dan Wilga (gribnif)
Fixed By: 
  • Dan Wilga (gribnif)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115

26 August, 2026 - 19:43
Project: LDAP / Active Directory IntegrationProject machine name: ldap_authDate: 2026-August-26Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Proof/TD:AllVulnerability: Information DisclosureAffected versions: <2.2.1CVE IDs: CVE-2026-81205Description: 

This module enables users to authenticate using LDAP or Active Directory credentials.

The module does not sufficiently sanitize user-supplied input before incorporating it into an LDAP search filter. This allows an attacker to discover additional information they should not normally be able to.

Solution: 

Install the latest version:

  • If you use the LDAP / Active Directory Integration module, upgrade to LDAP / Active Directory Integration 2.2.1.
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Harshvardhan Soni (sharsh)
  • Sudhanshu Dhage (sudhanshu0542)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114

26 August, 2026 - 19:42
Project: Entity PDFProject machine name: entity_pdfDate: 2026-August-26Security risk: Moderately critical 13 ∕ 25 AC:None/A:User/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <2.1.5CVE IDs: CVE-2026-81164Description: 

The Entity PDF module can create a PDF from any entity based on any View mode.

This module does not check entity view access when fetching a PDF route. This could result in a user accessing a PDF of an entity that they should not be able to view.

Solution: 

Install the latest version:

  • If you use the Entity PDF module for Drupal upgrade to Entity PDF 2.1.5.
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Italo Mairo (itamair)
  • Wesley Sandra (weseze)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113

26 August, 2026 - 19:41
Project: Entity APIProject machine name: entityDate: 2026-August-26Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Information disclosureAffected versions: <1.8.0CVE IDs: CVE-2026-81158Description: 

The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties.

The module doesn't correctly apply access controls for JSON:API entity collection endpoints. This exposes an information disclosure vulnerability.

This vulnerability is mitigated by the fact that the JSON:API module must be enabled in combination with the Entity API module.

Solution: 

Install the latest version:

  • If you use the Entity API module, upgrade to Entity API 8.x-1.8.
Reported By: 
  • Douglas Groene (dgroene)
  • Matt Glaman (mglaman)
Fixed By: 
  • Sascha Grossenbacher (berdir)
  • Klaus Purer (klausi)
  • Kristiaan Van den Eynde (kristiaanvandeneynde)
  • Matt Glaman (mglaman)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112

26 August, 2026 - 19:40
Project: DXPR Builder: The Best Editing (AI) Experience for DrupalProject machine name: dxpr_builderDate: 2026-August-26Security risk: Moderately critical 14 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Information DisclosureAffected versions: <2.8.1CVE IDs: CVE-2026-81162Description: 

The DXPR Builder module provides a visual / AI page builder for Drupal. The module uses a JSON Web Token for licensing, user license management, AI services, and subscription metadata.

The 2.x version of the module does not sufficiently restrict access to API credentials in JavaScript settings. When AI agent features are enabled, the token is exposed to all page visitors (including anonymous users) via drupalSettings.

This vulnerability is mitigated by the fact that a site must have DXPR Builder AI features enabled and configured with an API token.

Solution: 

Install the latest version:

  • If you use the 2.x branch of the DXPR Builder module, upgrade to DXPR Builder 2.8.1 or later.
  • The 3.x branch is not affected as it proxies AI requests through the contributed AI module.
Reported By: 
  • jurriaanroelofs
Fixed By: 
  • jurriaanroelofs
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111

26 August, 2026 - 19:39
Project: Disable Login PageProject machine name: disable_loginDate: 2026-August-26Security risk: Moderately critical 13 ∕ 25 AC:None/A:None/CI:None/II:None/E:Proof/TD:AllVulnerability: Access bypassAffected versions: <1.1.4CVE IDs: CVE-2026-16647Description: 

This module enables you to disable access to the /user/login form unless a secret key is provided.

The module does not invalidate the relevant caches when login page access restrictions are enabled. As a result, previously cached login page responses may remain accessible until caches are cleared. An attacker may continue to access the login page despite the restriction having been enabled.

Solution: 

Install the latest version:

  • If you use the Disable Login Page module, upgrade to Disable Login Page 1.1.4.
Reported By: 
  • Brian Osborne (bkosborne)
  • Jason Partyka (partyka)
Fixed By: 
  • Brian Osborne (bkosborne)
  • Jason Partyka (partyka)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110

26 August, 2026 - 19:38
Project: Disable Login PageProject machine name: disable_loginDate: 2026-August-26Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <1.1.4CVE IDs: CVE-2026-18260Description: 

This module enables you to disable access to the /user/login form unless a secret key is provided.

The module does not sufficiently restrict repeated attempts to guess that key, allowing brute-force attacks against the access-control mechanism.

Solution: 

Install the latest version:

  • If you use the Disable Login Page module, upgrade to Disable Login Page 1.1.4.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Brian Osborne (bkosborne)
  • Jason Partyka (partyka)
Coordinated By: 
  • Neil Drumm (drumm) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security
  • « erste Seite
  • ‹ vorherige Seite
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • nächste Seite ›
  • letzte Seite »

Benutzeranmeldung

  • Registrieren
  • Neues Passwort anfordern

Aktive Forenthemen

  • Canvas Palette: Eine fertige Komponentenbibliothek für Drupal Canvas
  • Hilfe zu Updates oder Composer
  • Vergleich Drupal und Contao
  • [geloest] Blocks in Bootstrap nebeneinander darstellen und nicht untereinander
  • DrupalCamp Frankfurt 27-28 November 2026
  • Bitte mein Bentzerkonto löschen
  • Beim Aufruf einiger Inhalte erhalte ich folgende Fehlermeldung
  • Neuinstallation: vermutlich ein rewrite-Problem
  • Drupal CMS installieren
  • [erledigt]MP3 in Drupal 10 einbinden
  • (gelöst)Drupal 11 installieren
  • Titel ausblenden
Weiter

Neue Kommentare

  • Danke ich werde mir die
    vor 2 Wochen 3 Tagen
  • Vielen Dank für Ihren
    vor 2 Wochen 6 Tagen
  • Composer ist sehr ratsam
    vor 3 Wochen 23 Stunden
  • Vielen Dank für den
    vor 3 Wochen 3 Tagen
  • Die alten CMS Vergleiche von contentmanager.de
    vor 3 Wochen 3 Tagen
  • Gut gemacht
    vor 3 Wochen 3 Tagen
  • Layout Builder etc. z.B. für Landing Pages
    vor 3 Wochen 3 Tagen
  • Links
    vor 3 Wochen 6 Tagen
  • Moin,wow, sehr gutes
    vor 4 Wochen 13 Stunden
  • Dass ist eine spannende
    vor 4 Wochen 21 Stunden

Statistik

Beiträge im Forum: 250316
Registrierte User: 20564

Neue User:

  • Robertspaft
  • drupalthemes
  • rofilm

» Alle User anzeigen

User nach Punkten sortiert:
wla9466
stBorchert6003
quiptime4972
Tobias Bähr4019
bv3924
ronald3857
md3717
Thoor3678
Alexander Langer3416
Exterior2903
» User nach Punkten
Zur Zeit sind 0 User und 42 Gäste online.

Drupal Security

  • Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191
  • Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190
  • CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189
  • Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188
  • AI CKEditor - Moderately critical - Code execution via Twig templates - SA-CONTRIB-2026-187
Weiter

Hauptmenü

  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche

Quicklinks I

  • Infos
  • Drupal Showcase
  • Installation
  • Update
  • Forum
  • Team
  • Verhaltensregeln

Quicklinks II

  • Drupal Jobs
  • FAQ
  • Drupal-Kochbuch
  • Best Practice - Drupal Sites - Guidelines
  • Drupal How To's

Quicklinks III

  • Tipps & Tricks
  • Drupal Theme System
  • Theme Handbuch
  • Leitfaden zur Entwicklung von Modulen

RSS & Twitter

  • Drupal Planet deutsch
  • RSS Feed News
  • RSS Feed Planet
  • Twitter Drupalcenter
Drupalcenter Team | Impressum & Datenschutz | Kontakt
Angetrieben von Drupal | Drupal is a registered trademark of Dries Buytaert.
Drupal Initiative - Drupal Association