Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81158

The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties.

The module doesn't correctly apply access controls for JSON:API entity collection endpoints. This exposes an information disclosure vulnerability.

This vulnerability is mitigated by the fact that the JSON:API module must be enabled in combination with the Entity API module.

DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - Information Disclosure - SA-CONTRIB-2026-112

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81162

The DXPR Builder module provides a visual / AI page builder for Drupal. The module uses a JSON Web Token for licensing, user license management, AI services, and subscription metadata.

The 2.x version of the module does not sufficiently restrict access to API credentials in JavaScript settings. When AI agent features are enabled, the token is exposed to all page visitors (including anonymous users) via drupalSettings.

Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111

Date: 
2026-August-26
CVE IDs: 
CVE-2026-16647

This module enables you to disable access to the /user/login form unless a secret key is provided.

The module does not invalidate the relevant caches when login page access restrictions are enabled. As a result, previously cached login page responses may remain accessible until caches are cleared. An attacker may continue to access the login page despite the restriction having been enabled.

Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110

Date: 
2026-August-26
CVE IDs: 
CVE-2026-18260

This module enables you to disable access to the /user/login form unless a secret key is provided.

The module does not sufficiently restrict repeated attempts to guess that key, allowing brute-force attacks against the access-control mechanism.

Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-2026-109

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81166

The Digital Signage Framework module provides a route that signage devices can call to refresh dynamic blocks on a display.

The route did not check whether the requester was a signage device, nor whether the requested block was one that the module delivers to displays. As a result, an anonymous visitor could read the rendered content of blocks they were not meant to see.

This vulnerability is mitigated by the fact that many block plugins perform their own access checks on the content they display, which limits what can be disclosed through this route.

Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81269

This module enables you to store structured data in configurable fields and expose Data Field values through JSON endpoints.

The module doesn't sufficiently check access when returning Data Field values through its JSON endpoint. This may allow anonymous users to access field values belonging to entities they cannot otherwise view, including unpublished content.

Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81161

The module provides a permission that allows users to configure email templates containing Twig code. This permission was not marked as restricted.

A site administrator might inadvertently grant this permission to less-trusted users. This would allow those users to execute Twig within email templates, and to gain access to functionality and information intended only for highly trusted administrators.

Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-2026-106

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81159

This module integrates Drupal Commerce with the CyberSource payment gateway.

The module does not correctly verify the integrity of data returned by the payment provider. A timing attack could allow an attacker to trick the site into registering that payment has been received even if it hasn't.

This issue only affects the Secure Acceptance Hosted Checkout gateway integration.

CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81168

This module enables site administrators to require CAPTCHA confirmation on specific pages.

The module does not sufficiently validate its CAPTCHA verification cookies. Under certain circumstances, an unauthenticated user or automated bot can forge the cookie and bypass CAPTCHA verification entirely.

Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104

Date: 
2026-August-26
CVE IDs: 
CVE-2026-81165

This module enables users to display a field of a target entity through a Blazy Filter plugin shortcode.

The module does not consistently check entity view access. If a user has access to a Blazy-enabled text format, this allows them to render a field from an entity they are not permitted to view.

The issue is mitigated by the fact that the shortcode does not expose the entire entity. Only fields that the shortcode can render are vulnerable.

Pages

Subscribe with RSS Subscribe to Security advisories