Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Islandora - Moderately critical - Access bypass - SA-CONTRIB-2026-126

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Islandora - Moderately critical - Access bypass - SA-CONTRIB-2026-126


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Islandora - Moderately critical - Access bypass - SA-CONTRIB-2026-126
  • Date: Wed, 2 Sep 2026 16:32:47 +0000
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/HXEHGALLSVDGHXS7BJQ7IBOEQJJCA6O7/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b="EmSd/nGg"; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=Gli57A5K; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=E4xpjNrT; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-126

Project: Islandora [1]
Date: 2026-September-02
Security risk: *Moderately critical* 12 ∕ 25
AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Affected versions: <2.19.0
CVE IDs: CVE-2026-84916
Description: 
This islandora_advanced_search sub module enables AJAX updates for advanced
search, facet, and search result blocks.

The module doesn't sufficiently check block access when arbitrary block ID's
are submitted to its publicly accessible AJAX endpoint. This may allow an
unauthenticated attacker to retrieve restricted block content.

This vulnerability is mitigated by the fact that an attacker must know or
guess a restricted block’s machine ID, and the block must contain sensitive
content protected by block access or visibility restrictions. Additionally,
the submodule is not known to be used by any modern Islandora configurations.

Solution: 
Install the latest version:

* If you use the Islandora module, upgrade to the latest version Islandora
2.19.0 [3]. Be sure to read the release node for advice on updating

Reported By: 
* Joe Corall (joecorall) [4]

Fixed By: 
* Annie Oelschlager (annieoelschlager) [5]
* Joe Corall (joecorall) [6]

Coordinated By: 
* Swan Kalata (akalata) [7] of the Drupal Security Team
* Bram Driesen (bramdriesen) [8] of the Drupal Security Team
* Greg Knaddison (greggles) [9] of the Drupal Security Team
* Juraj Nemec (poker10) [10] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [11]

[1] https://www.drupal.org/project/islandora
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/node/3620267
[4] https://www.drupal.org/u/joecorall
[5] https://www.drupal.org/u/annieoelschlager
[6] https://www.drupal.org/u/joecorall
[7] https://www.drupal.org/u/akalata
[8] https://www.drupal.org/u/bramdriesen
[9] https://www.drupal.org/u/greggles
[10] https://www.drupal.org/u/poker10
[11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3619358

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Islandora - Moderately critical - Access bypass - SA-CONTRIB-2026-126, security-news, 02.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang