Project:
Date:
2026-March-11
Vulnerability:
Access bypass
Affected versions:
<1.7.0
CVE IDs:
CVE-2026-4933
Description:
This module creates permissions per node content type to control access to unpublished nodes per content type.
The module does not consistently control access for unpublished translated nodes.
Solution:
Install the latest version:
- If you use the Unpublished Node Permissions module, upgrade to Unpublished Node Permissions 8.x-1.7.
Reported By:
Fixed By:
Coordinated By:
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team