it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-132
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-132
- Date: Wed, 2 Sep 2026 16:38:33 +0000
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/KBJYTU73TY6YBQF4KI7VUYTZ7OLYRTZD/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=XmXWpTup; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=HLDhdey4; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=2h8RbbY6; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::136 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-132
Project: Unpublished Node Permissions [1]
Date: 2026-September-02
Security risk: *Critical* 15 ∕ 25
AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:All [2]
Vulnerability: Access bypass
Affected versions: <1.8.0
CVE IDs: CVE-2026-84920
Description:
This module creates permissions per node content type to control access to
unpublished content.
The module has allowed view access for published content, overriding other
access mechanisms that might have been in place.
Solution:
Install the latest version:
* If you use the Unpublished Node Permissions module, upgrade to Unpublished
Node Permissions 8.x-1.8. [3]
Reported By:
* Erwin Eggenberger (eeg) [4]
* Jon Jordan (joncjordan) [5]
Fixed By:
* Fabien Gutknecht (fabsgugu) [6]
* Jon Jordan (joncjordan) [7]
Coordinated By:
* Swan Kalata (akalata) [8] of the Drupal Security Team
* Damien McKenna (damienmckenna) [9] of the Drupal Security Team
* Neil Drumm (drumm) [10] of the Drupal Security Team
* Juraj Nemec (poker10) [11] of the Drupal Security Team
* Pierre Rudloff (prudloff) [12] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [13]
[1] https://www.drupal.org/project/unpublished_node_permissions
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/unpublished_node_permissions/releases/8.x-1.8
[4] https://www.drupal.org/u/eeg
[5] https://www.drupal.org/u/joncjordan
[6] https://www.drupal.org/u/fabsgugu
[7] https://www.drupal.org/u/joncjordan
[8] https://www.drupal.org/u/akalata
[9] https://www.drupal.org/u/damienmckenna
[10] https://www.drupal.org/u/drumm
[11] https://www.drupal.org/u/poker10
[12] https://www.drupal.org/u/prudloff
[13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3613793
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-132, security-news, 02.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.