Date: 
2026-August-05
Vulnerability: 
Access bypass
Affected versions: 
<2.1.1
CVE IDs: 
CVE-2026-18985
Description: 

This module provides formatters to allow in-place editing in a View or other display (full content, teaser...).

The module doesn't sufficiently check access when editing entities. A malicious user could craft requests to allow them to modify any field on any entity.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit in place field editing permission".

Solution: 

Install the latest version:

  • If you use the Edit in-place field module for Drupal, upgrade to 2.1.1
Reported By: 
Coordinated By: