Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Taxonomy Term Glossary - Critical - Access bypass - SA-CONTRIB-2026-152

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Taxonomy Term Glossary - Critical - Access bypass - SA-CONTRIB-2026-152


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Taxonomy Term Glossary - Critical - Access bypass - SA-CONTRIB-2026-152
  • Date: Wed, 9 Sep 2026 17:24:27 +0000
  • Arc-authentication-results: i=2; smtp3.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=R+0RL5ON; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=YN+DhOfF; arc=none smtp.remote-ip=54.240.27.34
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org A26366FA74
  • Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org D14CC4065E
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788976022; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=LoSBuXbUbLnMVQY59A1u53hhSFtcyH5vHxFdKdxArqQ=; b=iT1LujR01QHjZdjfKRWoN+iGSGSHN/EsW81sZCKGuILxf6aFMqv7Smv+NRTgA2FNjnWC B6WE3eZmykVr7TAgh3PWrxahKVjCRnrn1Zlzzm5cwUXIrYhyTFYA37jKH+zwW/ED18kuJ YVFrM+Jwl7Y47NN3SfcDR+OwX6r+/29Y/8dJsmXJP4JSywlSQ4z3705uQol8uNaiADAPT e+vHouM6FUaWzNOAGVePsIm72buUlwLo11sLeLGqx3ets7gMHq1g7YbOB5teBNhw/wgYz sQZwb5x26RyYJqFvRkLyZ1x2wGdcEOhy+e+0K9f1OiPxAPcx0EvOuylzemywUtuVJfg==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974668; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=hspn330suWASPvT378JBRuwHJ9nqBYNK7lyNRoPyRNg=; b=HLsB11ztR74xT1+AOFNe4MkKqn0nI9gcH+WjeHE+iBIv5c1k6+LpFYnIszCA+7S4sSFY TwRF+QTH5SxdUk1IW6uKabaJNNCyo8o3nDFU04JbZIvZ4zRVUV+H9G18PnzCPz5utA2SC pe2mX7mFsGjopGaa0O0fDoU5CEvzvMC9pZNuGTaJ1mjxUfAbZxXYZqKGeW6gWRE0NcQFD /zPtW/NikM8LO9K/a0KsGbPz3MqBqMD+K99mjZ8pp7CaR0CouxXloTYi1UOpbj/0uwEkc k4x29kehItM342QKz6+piVRkpJZcgQZ00Wk1Iuo2e5OaiYNAhFiwkRRZISvWVmCe3xg==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788976022; b=leQV/BYB0FlypBw8LjWHA5l77WPNBets5Zip7EHjK2jpzu5NclSDyX11OvAxPvZOSqnd Cg01l0D/+Toxy3bbJodWdbBIRNt9VJK5PB+Db7sieX99imJSojj0EA3zWsQL85ZUmZBKn UmGlhpd/1kh5TH3RXZFwm20yO/AUmoAlpR+6HTI+DOUQ41Pl8mpH4PsPZ5+an1S2g3gG/ KpUlcCRtjkDJFkk+UP/cEIz1YauztGUNQtmOkNfOu5QYEQhF5uS0ajm5wP3+/eESdjV5e D5YlVQOBDr+07Cc3gIbdEm0hnu3965aS+nYasa6FZE/Pxy1T8C57W4q/XNMxtW/uzOw==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974668; b=ZyhKPg7eGzMCaFE6puob+L95u6PqYZKXzkITGmBTOyrTjwXAtsnRVknU5krua74NiaYf Yew6PbHQVklGfY4MR17819QI6e4fJdXVhbDySNVJ0rNbU1VgQBUWudQ3kYmulmun930xX 1xFXKyq2JXAYzbpqmGbyowPp4AostRfyQxC+AiN2d9Qp6e84uP4/5PcQzPgVYrtD6QoDY WePWbGBOdYiMJuBExcpSKD8txtGWYpgarj4pW9F7QOkXyuOLrrZRmXf4Kn7jj9Z9jHFUl Oaii0xCsK1O94ud9aocN3D++autAad1uUM0rUg950jsO3mLPbvjAVc42NSMZ6n3l6+g==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/64JWTRCEEI6U5G3CLMJ5IOIJHOTYM4B5/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=bC1APTmn; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=R+0RL5ON; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=YN+DhOfF; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::136 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-152

Project: Taxonomy Term Glossary [1]
Date: 2026-September-09
Security risk: *Critical* 15 ∕ 25
AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Affected versions: <4.6.0
CVE IDs: CVE-2026-87954
Description: 
This module adds automatic highlighting of taxonomy terms in content.

The module doesn't sufficiently check access on taxonomy terms. As a result,
anonymous users can view any of the site's taxonomy terms at the module's
JSON endpoint, including taxonomy terms that are unpublished or otherwise
restricted.

Solution: 
Install the latest version:

* If you use the Taxonomy Term Glossary module, upgrade to term_glossary
4.6.0 [3].

The 4.4.x and 4.5.x branches are no longer supported.

Reported By: 
* Hemant Gupta (guptahemant) [4]
* Marcus Johansson (marcus_johansson) [5]
* Serhii Checheniev (serhii-che) [6]

Fixed By: 
* Frank Mably (mably) [7]

Coordinated By: 
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team
* Swan Kalata (akalata) [11] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [12]

[1] https://www.drupal.org/project/term_glossary
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/term_glossary/releases/4.6.0
[4] https://www.drupal.org/u/guptahemant
[5] https://www.drupal.org/u/marcus_johansson
[6] https://www.drupal.org/u/serhii-che
[7] https://www.drupal.org/u/mably
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/xjm
[11] https://www.drupal.org/u/akalata
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3620593

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Taxonomy Term Glossary - Critical - Access bypass - SA-CONTRIB-2026-152, security-news, 09.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang