Project:
Date:
2026-February-25
Vulnerability:
Access bypass
Affected versions:
<2.0.4
CVE IDs:
CVE-2026-3210
Description:
This module enables you to add icons to CKEditor.
The module doesn't sufficiently add custom permissions to the dialog and autocomplete routes, allowing full access to the routes in most scenarios.
Solution:
Install the latest version and review permissions:
- If you use the Material Icons module for Drupal, upgrade to Material Icons 2.0.4.
- Assign the newly created "use material icons" permission to users who should have access to the widgets.
Reported By:
Fixed By:
Coordinated By:
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Ra Mänd (ram4nd), provisional member of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team