Needs review
Project:
Drupal Security Team
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
2 Jul 2026 at 22:53 UTC
Updated:
8 Sep 2026 at 16:42 UTC
Jump to comment: Most recent
May we please get a CVE ID reserved for the View Reference Filter exploit described in https://security.drupal.org/node/184441?
Attached is the CVE json that will be updated with:
• the HeroDevs directory URL when it's ready
Current properties:
• it has Tag1's URL already
• date is set Tag1's release
The rating I've given it is Medium (6.9), which aligns with Tag1's "moderately critical."
| Comment | File | Size | Author |
|---|---|---|---|
| CVE-2026-TBD-entityreference_filter.json_.txt | 7.5 KB | aangel |
Comments
Comment #2
gregglesMoving to "needs work" for the Herodevs post to be made and added to this and and then I can publish it.
Comment #3
aangel commentedGreg, I need the CVE ID before I can publish it.
Comment #4
gregglesSure, the CVE is CVE-2026-16136