Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013
  • Date: Wed, 16 Sep 2026 16:21:06 +0000
  • Arc-authentication-results: i=2; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=tEwNcO+e; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=Z2WYsTlk; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=tEwNcO+e; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=Z2WYsTlk; arc=none smtp.remote-ip=54.240.27.34
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 93EA0812B8
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 3C00E809CA
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1789577880; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=Zlq9S0ys6so6hNbHwabU+3mX6V8A/4OC1wksdU6cuxg=; b=EmrDiwRsr65+7ydiUjX9cpjEbhpG+frqpUme5A6evDnuJevwYdhMlWs/HbmWt25EakEb b5n119azqXfuau9psRKjOdrUQXwiPCJq3FK5NSLo9J3guH6m6mj4I1yI9cBoj30ijlyEM xeza2dVzZruDWVr6dCKRapNULyTL7RMGQ5X6sRy0f/VQRdMmWG5xr6cBssvikKcC9j3cf oyosyA5iB0pV5NZhBDyyB0sW4SmMo7JOM4OSpdXxlOipYx9PB7VdP2MSf+1KUG8UOPoHp NRGP7xXl5YF4rqld4i1tcrEVIzwf8vVRvfGLHgqTY3tcTvB0JiPJwgBDbLuONxL8nTg==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1789575667; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=dJR5MvutuNzEaQrA89DrEFQx1gMMuDUAajwYGeDBocs=; b=FenA1e9ycfwDCe/gadxLZSIbiVRVG5FlP6ZBdB9D0PZxkpwwfCmDv1MQ5hClfjIChBCS UibvKbI6QVh3QMtNFA0Fo7oZLk8dK5fPJxu5T9Uq5VmvZJ1injKZd0MWsF8UMPQJMlB/Y zGgCkfOBLQpSyy7XOyRxsppknauUc4aBZRVp451JaBj31tEuXlEI+dUlv5sxpawtjdIF5 kgm6be5sOIQgIYFDwYHuza15mIerY6M5ISUcuiPkZWZpjuUlabsbsWhCLRDhOJZJqAy6/ GWw6LdISWHpVYr95BJ9jlvDcHLP5p0xorIr5AXzmHrEUue1h0b/YtmIt4FBCdeEvMNA==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1789577880; b=AOagG/tEk7Ex02WxM2xktmHmJD/XCHfZX7eHUaD4V4g5fh1rkTbIZK7Lz8/zjcn1V+Jl 3vLK/AKOC4vK0++Rm7ivmCmcKrr1Pe0cFS9SXgPAlY3fr5ZSmen4EC7nwFbp29FiDmujK pxOqM0ItT1v/0FyFQaA+0AeI9S06gXbAa9hCtNEtU7OWo2jY4h/4Dj1NNUgnMHDrGifUR TRt0bgtVnd5IXP4HHKjUPjRVMjUAZ5k2f60cJORhPzs6Pl6XMdeEJiKi5DMzCDlhcmzG2 ThHiv246DrKnmABQYiMJpoRQKrZ0fyJtZMO3XAtUMSnbHFW1KlVJyYIxyAqOgWz6jlg==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1789575667; b=Ir1Fg6AgsdmL7hFGKWIcqtZTleBhZDICTMcEYx48iohKKLTXS7MC6U+hs8P0g5hU+AK0 AsVsHIs5Na/qm087IhIWbBc84/XB+SD+TSmLOwKFCGAEoxuqxctjSmxGpKQxYevfPATOr GZDS7fxk6Ex3oufduiGWRSnvq6UksPMqj+PZpTQYXcZV/OaWC2DaMqIFwE6Gu3zSNetzI QkGs2I0FR2GP8UDReqcMZmhHmEjvMPlLMEMeRBXUpURjtEfSse1+59mr40N8npa5u0pBr Bp7jDK3DFbXKw16LBOLHKAiUgN/FNgSloH3IpggydTdk3mAybn4KUFKY5dzhmgrfGbA==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/5IX26GUUASN57JAO24UGAOEDNSGOIEGN/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=bF1HgC7f; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=tEwNcO+e; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=Z2WYsTlk; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-core-2026-013

Project: Drupal core [1]
Project machine name: drupal
Date: 2026-September-16
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Third-party libraries

Affected versions: >=10.5.0 <10.6.17 || >=11.0.0 <11.3.17 || >=11.4.0
<11.4.7
Description: 
The Drupal project uses the CKEditor [3] library for WYSIWYG editing.
CKEditor has released a security update that impacts Drupal [4].

Vulnerabilities are possible if Drupal is configured to use CKEditor for
WYSIWYG editing. An attacker that can create or edit content (even without
access to CKEditor themselves) may be able to exploit this Cross-Site
Scripting (XSS) vulnerability to target users with access to the WYSIWYG
CKEditor, including site admins with privileged access.

For more information, see CKEditor's security advisory:

* High-severity Cross-site scripting (XSS) in the engine package [5]

Solution: 
Install the latest version:

*Drupal 11*

* If you use Drupal 11.4.x, update to Drupal 11.4.7 [6].
* If you use Drupal 11.3.x, update to Drupal 11.3.17 [7].
* Drupal 11.2.x and below are end-of-life and do not receive security
coverage.

*Drupal 10*

* If you use Drupal 10.6.x, update to Drupal 10.6.17 [8].
* Drupal 10.5.x and below are end-of-life and do not receive security
coverage.

Note that Drupal 8 [9] and Drupal 9 [10] have both reached end-of-life.

.... Instructions for contributed modules

Site owners should also review their site following the protocol for managing
external libraries and plugins [11], as contributed projects may use
additional CKEditor plugins not packaged in Drupal core.

CKEditor has also released another CVE in today's release that does not
affect Drupal, but may affect custom plugins or other usecases:

* Low-severity Cross-site scripting (XSS) in the engine package [12]

Reported By: 
* Piotrek Koszuliński (Reinmar) [13]

Fixed By: 
* catch (catch) [14] of the Drupal Security Team
* Lee Rowlands (larowlan) [15] of the Drupal Security Team
* Mohit Aghera (mohit_aghera) [16], provisional member of the Drupal
Security Team
* Jess (xjm) [17] of the Drupal Security Team

Coordinated By: 
* Bram Driesen (bramdriesen) [18] of the Drupal Security Team
* catch (catch) [19] of the Drupal Security Team
* Greg Knaddison (greggles) [20] of the Drupal Security Team
* Lee Rowlands (larowlan) [21] of the Drupal Security Team
* Dave Long (longwave) [22] of the Drupal Security Team
* Jess (xjm) [23] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [24]

[1] https://www.drupal.org/project/drupal
[2] https://www.drupal.org/security-team/risk-levels
[3] https://github.com/ckeditor/ckeditor5
[4] https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-rh54-vffm-5fvp
[5] https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-rh54-vffm-5fvp
[6] https://www.drupal.org/project/drupal/releases/11.4.7
[7] https://www.drupal.org/project/drupal/releases/11.3.17
[8] https://www.drupal.org/project/drupal/releases/10.6.17
[9] https://www.drupal.org/psa-2021-06-29
[10] https://www.drupal.org/psa-2023-11-01
[11] https://www.drupal.org/psa-2011-002
[12] https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-v6mg-96c6-gmpq
[13] https://www.drupal.org/u/reinmar
[14] https://www.drupal.org/u/catch
[15] https://www.drupal.org/u/larowlan
[16] https://www.drupal.org/u/mohit_aghera
[17] https://www.drupal.org/u/xjm
[18] https://www.drupal.org/u/bramdriesen
[19] https://www.drupal.org/u/catch
[20] https://www.drupal.org/u/greggles
[21] https://www.drupal.org/u/larowlan
[22] https://www.drupal.org/u/longwave
[23] https://www.drupal.org/u/xjm
[24] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3623427

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013, security-news, 16.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang