it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081
- Date: Wed, 22 Jul 2026 17:53:36 +0000
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/CV4LFA5ZK2NORCP2FT3YW32M7DHQ6FUE/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=Q2ysM7Y7; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=S3LWeOCM; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=lCsROVX8; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp1.osuosl.org 57DA3814C0
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org D3EC0605D1
- Dmarc-filter: OpenDMARC Filter v1.4.2 smtp3.osuosl.org D3EC0605D1
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-081
Project: Internationalization Single Sign-On [1]
Date: 2026-July-22
Security risk: *Critical* 15 ∕ 25
AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Access bypass
Affected versions: <1.8.0
CVE IDs: CVE-2026-16639
Description:
In a scenario of a multilingual website with different domain names per
language, this module enables you to be automatically connected across the
language domains if you are logged on the main language domain.
The module doesn't sufficiently validate a short-lived token, allowing an
attacker to bypass access control and authenticate as a victim user.
This vulnerability is mitigated by the fact that an attacker must appear to
originate from the same client IP as the victim.
Solution:
Install the latest version:
* If you use the Internationalization Single Sign-On module upgrade to
i18n_sso 8.x-1.8 [3]
Reported By:
* Drew Webber (mcdruid) [4] of the Drupal Security Team
Fixed By:
* Florent Torregrosa (grimreaper) [5]
* Drew Webber (mcdruid) [6] of the Drupal Security Team
Coordinated By:
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Drew Webber (mcdruid) [9] of the Drupal Security Team
* Juraj Nemec (poker10) [10] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [11]
[1] https://www.drupal.org/project/i18n_sso
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/i18n_sso/releases/8.x-1.8
[4] https://www.drupal.org/u/mcdruid
[5] https://www.drupal.org/u/grimreaper
[6] https://www.drupal.org/u/mcdruid
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/mcdruid
[10] https://www.drupal.org/u/poker10
[11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3606350
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081, security-news, 22.07.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.