it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Ultimate Table Field - Critical - Access bypass - SA-CONTRIB-2026-153
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Ultimate Table Field - Critical - Access bypass - SA-CONTRIB-2026-153
- Date: Wed, 9 Sep 2026 17:25:01 +0000
- Arc-authentication-results: i=2; smtp2.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Y6r0AfnT; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=bd1xnjEm; arc=none smtp.remote-ip=54.240.27.115
- Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 5F465429B8
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org DB9A740703
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788976105; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=jmvvgbySVcVVecx4VHsecEkh5MXh7BZgXCpbY4RyXv4=; b=IEv1GqH40f8ndQlCBjwor66rmzw5REq/obpQYncYx8khnBju4uhlabuZPsO2yp4r2skp lVD1fPwK+e5gnf0uvh/cwEDBxvtGSa/S6UL7jcBM1eIVxbzx9JhBTDHNsfVoULzQa45pK BODCvB8Yy4u0t1KeR36g6ZPPgxA7RN3zSKel3LP/O7R9Dr93OeYlKEe9oxltwpaFeg0AI 3tK3yMjdcAp514xVcBuoiGmrEa+0wgTickkszawsjfptIOIUzJgGmJgQpV3TWqoeRmovE uxdiW3c+uETnhcnpEz9YqRTQ1kr3P9Hx56bz9103Ie/0VBpm2PA4dMc/4NMf2uwY+MQ==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974703; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=VHHII9rtJzSk93DvZhO0cJnQLmFzh2cCewS/M6l3nsk=; b=GMcGVTtgJpH3aj6kApi87TmStbNCw9hrct7xrvWUlXJx+LERz9cGqD94a1i/tV9pkptd AHs2JW/a3xlgWgCb6fbgWk+pHUJY6HOcUsRecmW+91SlGAfQ5lA1TyuiORppLuefEY80U BTDV4Q5/TiTWQJzvAB4lXp+sEzAB5AstiMFCSckDnBO2j4cONQ46AXgz9ev6vGFR+bPgG dywcDwxBDhbFy+YrNti2BJaGUIowlNK+roj3lcINZlslzj0tDg60poz6AosAkq6xn7Ssl yLVOs4/rZUUfw3ozxk4COMFGwgPkw2ZfT/Ynpv1zdIvD7w0M1FNCM3GF8e5Yt+V1HTg==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788976105; b=lWfAuN56zdpgCDiHgepEE0BFsIyEBdljBqExUr4DKDvtRnKCWcaSSQNXm6GKNYzgpRq8 WoRCvqSSU0Whws3ua/x+8r6BSb31lSGvsUaRApDfd5rVxrlKTUc59gK4FqClozc9heCxw m1QUU/I83utYsqflz9mCmIxCnFAmJuELyIr2yUww5Nm/oE75y3tkz2h4mRue70IM9zlLl 9ATaGJ6a8aWdP1xm+HFrKoVzTPj56vyhMHQFcDWSMhyx1nYTQJyqjrOvW1VUqih7kuB4i thQHfbWTYXc6SJ0t/YdHit0gkFRmpm38kfuc6YFU+a3XYlBYE00Zyccq7D0DfILJt9A==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974703; b=CmUiZknbiPvqCfq1NCf32fvOTtqCPuXgeU3cmyZbnrmkfzXNQh2dLQBu174NOAAGWpMr PVkIdE98DSfpZwwDYePwDMQYF1KI+CYLSegouuZELlmND0raLUDNjFNFX3cbct6m6J3vK 0Ai9q1AavJV6xA4H8Yxm+efmjw6F/mdxBOJSZtSjz3yUMlGzG8j53BGYmEBWX8GALKBmS IMVWeL97p6OCx/nKJNBV1ZL27ZcC8O476IEdMKkeRZUdgc40JPvFNSpWW2ZVwU0PsqC0N 30rTIxOlhIJVE9NaxXnXl3s8C9x/uy6GdK2HVfRADrXFPIyemI3FDwemXPeOGG+X/WQ==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/OZ4BRF6TB7Z3L75PTLI7INQC7YGX6M2O/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=f0+XcT1w; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Y6r0AfnT; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=bd1xnjEm; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-153
Project: Ultimate Table Field [1]
Date: 2026-September-09
Security risk: *Critical* 15 ∕ 25
AC:None/A:None/CI:None/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Access bypass
Affected versions: <1.1.1 || >=2.0.0 <2.0.1
CVE IDs: CVE-2026-87955
Description:
The Ultimate Table Field module enables you to store table data in a field
and edit each table cell through a dialog, using cell field plugins such as
text, link, and file.
The module doesn't sufficiently protect the route that opens the cell editor
dialog. The route is accessible to anonymous users, who can open the dialog
for any cell type. The dialog allows uploading files to the server location.
This vulnerability is partially mitigated by the fact that only files with
the pdf, doc and docx extensions are accepted.
Solution:
Install the latest version and adjust permissions:
* If you use the 2.x branch of the Ultimate Table Field module , upgrade to
Ultimate Table Field 2.0.1 [3].
* If you use the 1.x branch of the Ultimate Table Field module , upgrade to
Ultimate Table Field 1.1.1 [4].
After updating, grant the new permission /Use the Ultimate Table Field cell
editor/ to every role that edits content containing an Ultimate Table field.
Without it, editors can no longer open the cell editor dialog.
Releases of the 1.0.x branch are not supported and do not receive security
coverage. Upgrade to 1.1.1 or 2.0.1.
Reported By:
* Marcus Johansson (marcus_johansson) [5]
Fixed By:
* Brahim Khouy (b.khouy) [6]
Coordinated By:
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team
* Swan Kalata (akalata) [11] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [12]
[1] https://www.drupal.org/project/ultimate_table_field
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/ultimate_table_field/releases/2.0.1
[4] https://www.drupal.org/project/ultimate_table_field/releases/1.1.1
[5] https://www.drupal.org/u/marcus_johansson
[6] https://www.drupal.org/u/bkhouy
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/xjm
[11] https://www.drupal.org/u/akalata
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3621005
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Ultimate Table Field - Critical - Access bypass - SA-CONTRIB-2026-153, security-news, 09.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.