it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Mailer Plus Log - Moderately critical - Access bypass - SA-CONTRIB-2026-128
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Mailer Plus Log - Moderately critical - Access bypass - SA-CONTRIB-2026-128
- Date: Wed, 2 Sep 2026 16:34:18 +0000
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/UWOSKJ2OU2EEC4ZC3BI2JPTE6SBHRSW3/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=kGA51C3K; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b="iwnbyZv/"; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=Uvy71zD1; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-128
Project: Mailer Plus Log [1]
Date: 2026-September-02
Security risk: *Moderately critical* 12 ∕ 25
AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Access bypass
Affected versions: <1.2.7
CVE IDs: CVE-2026-16648
Description:
This module enables you to log the emails sent by Mailer Plus as content
entities, so they can be reviewed at Reports > Mail log.
The module doesn't sufficiently redact the content of the emails it logs.
Account related emails are stored with their one-time login links intact, so
any user who can view the log can obtain a one-time login link for any
account, including user 1, and use it to log in as that account.
This vulnerability is mitigated by the fact that an attacker must have a role
with the permission View Drupal Symfony Mailer log entries, which in earlier
releases was not marked as a restricted permission.
Solution:
Install the latest version:
* If you use the Mailer Plus Log module (previously known as Symfony Mailer
Log), upgrade to Mailer Plus Log 1.2.7 [3]
* After updating, run database updates so that the email bodies already
stored in the log are redacted.
* Review who should have the View Drupal Symfony Mailer log entries
permission, and whether your site sends out custom sensitive emails that
would need to opt in to the redaction logic.
Reported By:
* Sven Decabooter (svendecabooter) [4]
Fixed By:
* Mohit Aghera (mohit_aghera) [5] provisional member of the Drupal Security
Team
* Sven Decabooter (svendecabooter) [6]
Coordinated By:
* Swan Kalata (akalata) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Mohit Aghera (mohit_aghera) [9]
------------------------------------------------------------------------------
Contribution record [10]
[1] https://www.drupal.org/project/symfony_mailer_log
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/symfony_mailer_log/releases/1.2.7
[4] https://www.drupal.org/u/svendecabooter
[5] https://www.drupal.org/u/mohit_aghera
[6] https://www.drupal.org/u/svendecabooter
[7] https://www.drupal.org/u/akalata
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/mohit_aghera
[10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3619706
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Mailer Plus Log - Moderately critical - Access bypass - SA-CONTRIB-2026-128, security-news, 02.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.