Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090
  • Date: Wed, 29 Jul 2026 17:08:34 +0000
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/NCEYT7GI3OCJHV2PXSGIOHEQGKJV33US/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=CQSbaUcX; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=gMX51JF0; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=KAcENdlU; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp2.osuosl.org 5878F4085B
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp4.osuosl.org 09255406DE
  • Dmarc-filter: OpenDMARC Filter v1.4.2 smtp4.osuosl.org 09255406DE
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-090

Project: Token Content Access [1]
Date: 2026-July-29
Security risk: *Moderately critical* 10 ∕ 25
AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon [2]
Vulnerability: Access bypass

Affected versions: <3.1.2
CVE IDs: CVE-2026-18259
Description: 
The Token Content Access module enables site administrators to provide access
to content using access tokens.

The module does not sufficiently protect access token comparison in some
cases. This could allow a persistent attacker to use a timing attack to guess
a valid access token and bypass access restrictions for content protected by
this module.

This vulnerability is mitigated by the fact that an attacker must know or
discover a URL for content protected by Token Content Access, and exploiting
the issue requires measuring timing differences in token comparison
responses.

Solution: 
Install the latest version:

* If you use the Token Content Access module for Drupal 10.x/11.x, upgrade
to Token Content Access 3.1.2 [3]

Reported By: 
* Robin (robincs) [4]

Fixed By: 
* Kyrylo Loboda (lobodakyrylo) [5]

Coordinated By: 
* Bram Driesen (bramdriesen) [6] of the Drupal Security Team
* cilefen (cilefen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Swan Kalata (akalata) [10] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [11]

[1] https://www.drupal.org/project/tca
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/tca/releases/3.1.2
[4] https://www.drupal.org/u/robincs
[5] https://www.drupal.org/u/lobodakyrylo
[6] https://www.drupal.org/u/bramdriesen
[7] https://www.drupal.org/u/cilefen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/akalata
[11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3611483

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090, security-news, 29.07.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang