Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Media Library Importer - Moderately critical - Access bypass - SA-CONTRIB-2026-129

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Media Library Importer - Moderately critical - Access bypass - SA-CONTRIB-2026-129


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Media Library Importer - Moderately critical - Access bypass - SA-CONTRIB-2026-129
  • Date: Wed, 2 Sep 2026 18:29:25 +0000
  • Arc-authentication-results: i=2; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=n9hhc2Et; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=LTUhgzvF; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=n9hhc2Et; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=LTUhgzvF; arc=none smtp.remote-ip=54.240.27.115
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org A5DB4612C1
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org 4B051606B0
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788373983; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=crCXtm3BGu4baJH7HFwa3UzPyIUnEhKBWEOfr+Wsx4U=; b=Gg3ao3S8zNJbXiZNb75ZZk6XO1GT9FLNKAWs1bMRgKYROdmi0pxzvv3tnYFG9jTVa6B0 khjnIKUwwRkDduJrtURn6mAi0HGb0mDbuChGMbNN4Cly3D1DpzcjNjYJ+Q/VhegYWfg8F wCYRQkrGdvKzQi0lXZr/b5CYh0ZSP/jeZQsG75a9z06hgsukOiwJ6WnubuqOPoJ36797O ePshhhdFGbf84oYOyCkoI1uxE470Hm8RvwSyyGETR9KCAuB0rhG4OKaZfqbA5GOT3a1Oa SHLyTbpcVOpOPA1Yw/oatW2xLziIVOZGcQ7p5vDd6TYg8pQDvkSYJIrjK4gg4+PG9uw==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788373767; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=TU3NK4KdEPrqY441eQjao0uuCojCfcSgmUezGU9qG+g=; b=HhG8TiNCHhe5TnsO9yf72fX7aIPDmiXcRweklD5oQio+OWWO46gP0fDM689XJWWDWzvg 1dVrv3IuyfbOgko6ue+OduLouRHWUdIETypohC+U2rY1+AH7TmKwM5dGdCzu6ACr5tLq/ SVOw5E1plnCyFPj1fwxKG4UdU4of6aq/6eua+jR7ZZswIHLL4mLzV6kNHX8LQf1YE+3Hm IuL8mtuiNazKmmyS0jR3knGPVan3Rm3kA7Ch8pL8tF8TCsjw+k1M5AmZGvuKm05CSOeTy eMpcsuy88SVi1CzUkGettfijZ0Gb7c/5DJOGjKyCxXjbU9w01utcuFZWVdkRorkxP8w==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788373983; b=AsvLJHBXpuQf/Gj64xLW7vVU0m0DUy2+Hrt112CLGHrtSPKMziYhiw8CNMbRjdoDkWEK bJmGyVeRBGeILDeP6WS4NUnqLM7gg5I48eR5JV3J+qbbU7EsF+ikTYKCgr6Fn827N0sXZ /EmXaPw6WVtu0lFLRO6i0oxthYv7pJj1bF2/olqU9J2eMN5ap4Wk1O2vbtYbaa2f8v41I jktlLRQTVhSdrtGWfE4fu8boFq0GJyF7d+6fsqLiJb4ctFgcPb4ihVpBw8aTxjI4UIMCq 2RexpaDGmiv2OPm45a14mkKlJx5z9XqlM14GcbwAqsSCN8VaxvfmyPzxZq/o/emgIEQ==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788373767; b=gqe/A/EGtrR9v/lbiUB30mmgIioPLaCdkj7MLnnoYjPKWJnvjT+o9vl73Vg8pL0NBeQx 9mfWwuo3g9NbZ12rTuP9oFTDV1dW4i0wVBm1Zd3rYI481MbWdW2PxasTpL8oKpFOxUJKu IFJ0FO9ZvgltAwrT/zerT6McpozApkcRB7aDiDtpLGCLdmzGakaGpO25JJnEFQDma+qMY AzZZ334dc4avCGI3yIjBBrMejpDnHZ97H60/JtvXJ48L0XEkoQlzhx6sST77c6Eu4jOJX u+LVDbtXOaYCnd4YnQ56hCIPDukZjE4xQ1D2c5JYbOtCMm5tm5203g1Am4lB0E2QDtQ==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/PUF3RKDZVJFJTN5SHAULKZTCBY7TSVDP/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=gfntNQBs; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=n9hhc2Et; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=LTUhgzvF; dmarc=pass (policy=none) header.from=drupal.org; arc=reject ("cv is fail on i=2"); spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.136 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-129

Project: Media Library Importer [1]
Date: 2026-September-02
Security risk: *Moderately critical* 11 ∕ 25
AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Affected versions: <2.1.6
CVE IDs: CVE-2026-81163
Description: 
A module to import media files into media library.

The import folder is a plain textfield with no validation. Point it at any
directory the web user can read, and the importer copies every file whose
extension matches a selected media type into the public files directory and
publishes it as a Media entity. Files that were deliberately kept outside the
webroot, such as a private file store, become downloadable by anonymous
visitors at a predictable URL.

Solution: 
Install the latest version:

* If you use the Media Library Importer module for Drupal upgrade to Media
Library Importer 2.1.6 [3]

Reported By: 
* Marcus Johansson (marcus_johansson) [4]

Fixed By: 
* Italo Mairo (itamair) [5]

Coordinated By: 
* Swan Kalata (akalata) [6] of the Drupal Security Team
* Greg Knaddison (greggles) [7] of the Drupal Security Team
* Juraj Nemec (poker10) [8] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [9]

[1] https://www.drupal.org/project/media_library_importer
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/media_library_importer/releases/2.1.6
[4] https://www.drupal.org/u/marcus_johansson
[5] https://www.drupal.org/u/itamair
[6] https://www.drupal.org/u/akalata
[7] https://www.drupal.org/u/greggles
[8] https://www.drupal.org/u/poker10
[9] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3615540

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Media Library Importer - Moderately critical - Access bypass - SA-CONTRIB-2026-129, security-news, 02.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang