Project: 
Project machine name: 
dkan
Date: 
2026-October-07
Vulnerability: 
Access bypass
Affected versions: 
<4.0.4 || >=4.1.0 <4.1.5
CVE IDs: 
CVE-2026-107267
Description: 

The DKAN module enables organizations and individuals to build open data portals in Drupal. The DKAN datastore imports tabular data files into database tables and exposes them for querying with a JSON API.

The module does not correctly check access for all of its endpoints, leading to a potential access bypass.

The vulnerability is mitigated by the fact that it is only impactful for sites that do not give "access content" permission to the anonymous role.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: