Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Key auth - Moderately critical - Access bypass - SA-CONTRIB-2026-138

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Key auth - Moderately critical - Access bypass - SA-CONTRIB-2026-138


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Key auth - Moderately critical - Access bypass - SA-CONTRIB-2026-138
  • Date: Wed, 9 Sep 2026 17:17:51 +0000
  • Arc-authentication-results: i=2; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=iEQh0vLy; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b="HEnsyY/4"; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=iEQh0vLy; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b="HEnsyY/4"; arc=none smtp.remote-ip=54.240.27.116
  • Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org B4BA84F08F
  • Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 81B124077F
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788976556; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=OHcyEj3cwYOHRa03P64Jx7fGQ7qDCXPXCFTBzP2TDvU=; b=gCg9cWY4i9RYR8+qt9L90HhUJFdhtFHtAs6sigDLQYCVHfkRBudTEnflzsmu5cwqUQPb RzViJn05Qo1hrVML8grgrbs73pCeif5tYgGgSGhPx5rlZjZFDtg1VW4hx32iskz+skcU7 xvhkPyKwOtnnNFRgIOuUiSPAeJVXG7PjSwAINGsnUpYB+1Krl4uuvY+gPt3JTHHiSPtTi l5t+V05CouxZxzfFDpEoUZA+d/zoFs27MF93lE/VzfsW7q1GnRW6vW/IIFj20xdWMnJ3Q U+0/+ic+qaY0+CzkbV6bec62AHQPz/hYohxxGcwL8faUSjilX5l5/mzCsxffCpRJyZQ==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974272; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=q2/rhtC78wqG3jRUeO6V47n1EuNl30tmDcoZSXRHtmM=; b=KjoCvxdRaXCOaDipt6irrh0t1V0/JsJNJmTdOEus/vmsWdE8f129/w0iNkvE8gGUeaB/ NuvGWur6l99onQG6/sm+yy45R0SrvXiLYvfqK8R7WiYHSFYLPYbaoppbHndTln76kpOzp tjQLBYUFJ/G91fB/3Cw6Xt/pDuZB0x1WRzLKOGyoYBxVGTxgfugCK+BVCnAiPUhBXzZih w/ypxIXUnLV+reBNcIJ8pfdf6wl4q3xwuPERHDiHWCHWE7I8Fg5hNNjdiNrgu3NJ/Gfxy UEhS6TCoKGoujBcV4YnE+991JvSfSioZU+xkk7cudZGkfadLQa/DccGbhO4HDLnJ7Bg==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788976556; b=lb1dFR5vZWnXWt4R2hAG+xFA4EOXwqE3JGsn+YwacQXrHt/mZPcYeyo4g9yyXaYr3HBv F6H3LEYyH9NFimIfTxW7piivSml7uw8sut8UskmLLM0SzGXvphZ6MK2oC+BfpKubQY2lM 8bKPLlsp82dbDH0CFi+KKNDpWfVzj+ewH3JN/o31ZEhqEbBKignnPNtV4XJLxP+uWu2Ki O/SFxA/x7bBdAUYEesQMPPSe0SoWHTpE9+WWilCAn38iRpE/Bfz/zzu7iJOl9Wgi+Iyhr q70h/3L+ho9gyLtWhel8l8uhzRpntSuEHFYyc76DlCgMwlamUObOKusn38JvKDWi/hg==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974272; b=sGVdTVGpLRfWpC7CATckn0jSOOVu4qthXMq+uNYiSilA9zyA8dPInEIEeTmQmeXb5xSh 3gAdApRzmH8GLWCJsUnib8RzFqVJY/K5hrlTPyrlBfcBj/qPQ17x68I25vYDhsPKKv3h2 sZjb3OUGw66zNuAM4r4cVn5XF65bTcz58jmJuuqleoD0xow55hoGMjlopXu0aOlpJak7T KtNSrlAe4Knu7EMNOTTpJBc/SF+kgzxPSIQYo7VaMKuyeAhmgU/g0Y8ycf0p7089lMp1p vtE/TZbzL/V49a/FcPXYmblt0ki84eOJEb1t/mLKZ0mRdYj/e4TAKhIONtNWKEAv7Aw==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/EOQTIS32ZU353YAPVY4UTG6KPWCPGV6U/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=g+YLpRW2; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=iEQh0vLy; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b="HEnsyY/4"; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-138

Project: Key auth [1]
Date: 2026-September-09
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Access bypass

Affected versions: <2.2.4
CVE IDs: CVE-2026-87940
Description: 
This module enables you to add key-based authentication on a per-user
basis.

The module doesn't cache per user, potentially allowing an attacker to view
another user's authentication keys, if the attacker has the same permissions.

This vulnerability is mitigated by the fact that the site must have the
dynamic_page_cache module enabled.

Solution: 
Install the latest version:

* If you use the Key Auth module, upgrade to Key auth 2.2.4 [3].

Reported By: 
* Utkarsh Choudhary (sisyphus_ut) [4]

Fixed By: 
* Utkarsh Choudhary (sisyphus_ut) [5]
* solideogloria [6]

Coordinated By: 
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team
* Swan Kalata (akalata) [11] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [12]

[1] https://www.drupal.org/project/key_auth
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/key_auth/releases/2.2.4
[4] https://www.drupal.org/u/sisyphus_ut
[5] https://www.drupal.org/u/sisyphus_ut
[6] https://www.drupal.org/u/solideogloria
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/xjm
[11] https://www.drupal.org/u/akalata
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3621829

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Key auth - Moderately critical - Access bypass - SA-CONTRIB-2026-138, security-news, 09.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang