Project machine name: 
editoria11y
Date: 
2026-September-23
Vulnerability: 
Access bypass
Affected versions: 
<2.2.23 || >=3.0.0 <3.0.9
CVE IDs: 
CVE-2026-96390
Description: 

This module runs a client-side accessibility checker that automatically reports results to dashboard views over an API.

The module incorrectly described a permission as a "view" permission when it grants edit and delete access to module data, resulting in a potential access bypass.

Solution: 

If you use the Editoria11y module, update the module and review permissions.

Review permissions: Make sure anonymous or untrusted authenticated users have not been given permission to use the checker. The permission is labeled as:

  • View Editoria11y checker up to and including 2.2.22/3.0.8, and
  • Run Editoria11y checker and report results with 2.2.23/3.0.9.
Reported By: 
Coordinated By: