Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108
  • Date: Wed, 26 Aug 2026 17:37:12 +0000
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/XBWAKEWZJCU3VSQNN6L5IOZKLAJNG7ND/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=cTIGZjE6; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=OR+JTCkR; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=etn3HK8a; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-108

Project: Data field [1]
Date: 2026-August-26
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All [2]
Vulnerability: Information disclosure

Affected versions: <2.0.13
CVE IDs: CVE-2026-81269
Description: 
This module enables you to store structured data in configurable fields and
expose Data Field values through JSON endpoints.

The module doesn't sufficiently check access when returning Data Field values
through its JSON endpoint. This may allow anonymous users to access field
values belonging to entities they cannot otherwise view, including
unpublished content.

Solution: 
Install the latest version:

* If you use the Data Field module, upgrade to Data Field 2.0.13 [3]

Reported By: 
* Marcus Johansson (marcus_johansson) [4]
* Drew Webber (mcdruid) [5] of the Drupal Security Team
* Steven Jones (steven jones) [6]

Fixed By: 
* Joseph Olstad (joseph.olstad) [7]
* NGUYEN Bao (lazzyvn) [8]
* Marcus Johansson (marcus_johansson) [9]
* Steven Jones (steven jones) [10]

Coordinated By: 
* Swan Kalata (akalata) [11] of the Drupal Security Team
* David Stoline (dstol) [12]
* Greg Knaddison (greggles) [13] of the Drupal Security Team
* Drew Webber (mcdruid) [14] of the Drupal Security Team
* Juraj Nemec (poker10) [15] of the Drupal Security Team
* Jess (xjm) [16] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [17]

[1] https://www.drupal.org/project/datafield
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/datafield/releases/2.0.13
[4] https://www.drupal.org/u/marcus_johansson
[5] https://www.drupal.org/u/mcdruid
[6] https://www.drupal.org/u/steven-jones
[7] https://www.drupal.org/u/josepholstad
[8] https://www.drupal.org/u/lazzyvn
[9] https://www.drupal.org/u/marcus_johansson
[10] https://www.drupal.org/u/steven-jones
[11] https://www.drupal.org/u/akalata
[12] https://www.drupal.org/u/dstol
[13] https://www.drupal.org/u/greggles
[14] https://www.drupal.org/u/mcdruid
[15] https://www.drupal.org/u/poker10
[16] https://www.drupal.org/u/xjm
[17] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3619186

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108, security-news, 26.08.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang