it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104
- Date: Wed, 26 Aug 2026 17:33:52 +0000
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/HFN5PQN27KZPJAFB2CJIV5D65GIA4LOF/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=Jq42kNy+; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=nNYWb68K; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=HGOo6fJZ; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-104
Project: Blazy [1]
Date: 2026-August-26
Security risk: *Less critical* 9 ∕ 25
AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:Uncommon [2]
Vulnerability: Access bypass
Affected versions: <3.0.18
CVE IDs: CVE-2026-81165
Description:
This module enables users to display a field of a target entity through a
Blazy Filter plugin shortcode.
The module does not consistently check entity view access. If a user has
access to a Blazy-enabled text format, this allows them to render a field
from an entity they are not permitted to view.
The issue is mitigated by the fact that the shortcode does not expose the
entire entity. Only fields that the shortcode can render are vulnerable.
Solution:
Install the latest version:
* If you use the Blazy module for Drupal, upgrade to Blazy 3.0.18 [3].
Reported By:
* Drew Webber (mcdruid) [4] of the Drupal Security Team
Fixed By:
* Gaus Surahman (gausarts) [5]
* Drew Webber (mcdruid) [6] of the Drupal Security Team
Coordinated By:
* Swan Kalata (akalata) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Jess (xjm) [9] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [10]
[1] https://www.drupal.org/project/blazy
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/blazy/releases/3.0.18
[4] https://www.drupal.org/u/mcdruid
[5] https://www.drupal.org/u/gausarts
[6] https://www.drupal.org/u/mcdruid
[7] https://www.drupal.org/u/akalata
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/xjm
[10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3616954
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104, security-news, 26.08.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.