Project: 
Date: 
2026-August-12
Vulnerability: 
Access bypass
Affected versions: 
<2.0.1 || >=2.1.0 <2.1.1
CVE IDs: 
CVE-2026-73478
Description: 

This module enables you to view the differences between revisions on any entity type.

The module doesn't sufficiently restrict access to non-node entity revision diffs.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to view the entity.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: