Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] REST & JSON API Authentication for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2026-182

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] REST & JSON API Authentication for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2026-182


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] REST & JSON API Authentication for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2026-182
  • Date: Wed, 23 Sep 2026 17:10:01 +0000
  • Arc-authentication-results: i=2; smtp1.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="NGW/fwc6"; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=jnc4DNXf; arc=none smtp.remote-ip=54.240.27.116
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org DC7A485429
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org 6C431606BD
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790186671; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=Eho1CB7QI7dkvGrR2ynETQ6AwWFuHE7stzMsdrtKPxU=; b=F0N7T3WFREssDMILZ0B703vPjLTxMju8BwwF3qb67ru0BPo5X3FUcw0piXipV5iAaLhg WTS4Mc0inVlf3r4p8gmiferu2AlKsdgra7YBRobFMpeG4z5G1u4bdyUMMw4DhSL65b53d olfH+kXSTVps/Bj8Pb2fl8AnDeFFBGX2k5RT54uoVTMjSk5oQW82Tpp+ZXHdDBGIkMlID Ef9iai4fxXHrADuRgd2ERj7BGa7T7OddAe895REY3OzS/1Gi0lDSXf7yXa/An0dltmnrm LKxicD+jDMZ/gzxxK410Ok2k8BOfyIzJfynu2G9/o/duTMSoG2fUz13hsae8KEqDxnQ==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790183402; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=aX9ugJXyb4tnKI/V2mwTMFOVokIgQ+uvVge7GwEdLhw=; b=DPAVOV7YF8Eh1qdF9Tuk7mWx6iH345nezu035EbcW2/tE+MKMH1VJuCJDDB1tcCza2Ax S2LoJMkHh5wn4Y0rYJyZOfsziXHr7RUqDS0FRdIZMg/nx+dvClRMCIGXyo32VFGnhWjLj LN04qwUzQNezcmeRGh68gNbOJooeeCn4bvpqbYfqTBieGKKM5xDcuTr6A11QdV3mO4+j0 1Y/0fEIjIlkk409kin8gynCkp7Poete4tZxczwYhV+ZG+OuC8x5/8gPLfvlPID7YM+m3a MGebeHk4cOfP6g7XdslpYN5S9+q+xvZMb0gDgbcm9NhcvRyzHE8ZD0heP8N0P9rI4Ow==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790186671; b=T4cBFfzsIGrq1f0Z9zN2+iMeSbuMCgwS795ATKTynLisnrTwB1iDb62WGY1lAiUzUQHn C0RmnosUActtFqcrgi4aI13et5QjC/Vo1SLJZmRvBe8/1pLNJZcTIo3AzrlXNEuySDPNB g5rpgbW6r3sjdEPvXw3cY1FNsYzuRLuCOxrJOv+/xnYHnboXUqxqZ5w4ylG5fm7qeZAcu VPdzWQXaqWEo9mw5BnPQRMrcG9+JuTwk4Z6Q4hezLIotQs/EMzCpDzVeyWPW0Vb/2VilO 1exv3X4zYo/3U7IbcSCQ9IE2Tgug8kiy8KdGtZzrYE66XLmLERCEdOuvfM/wmcSS6+Q==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790183402; b=RmNRmFOdiJD0nFgrCVKpwhRMzFQZnZvXoddYj6zudCfiC1jBpB4wWdOUS5MthWObNSE7 yO8JRP5/if2CGLWAZbp1idguz+nHHWclkTW5ue+L8oe/gADcnbReZ+qHHzLAXIbUD8V8T 5JVgxsiHLgLKNs8HaJ6FBQaX56j9p/hwPTyKUjDF+zFtzJknCv3sukeVjItsSnxiGszb7 xCL3U1pVrhAHwG/1i9xTko63J7zHw6AUbdr4BT1hV0iLilGfBEDdw6rayFxGrZZINdP8H cMveqDCXOELA32EMJFPa/DxUh2xfkuDHzWqGGrNHMyaRVtUr07x8MdlDcS12Bs+8CzA==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/NERSSC5V4BL45CSEGJ4QIREJGEFPMCHY/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=Ha15kyQw; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="NGW/fwc6"; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=jnc4DNXf; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-182

Project: REST & JSON API Authentication for Drupal [1]
Project machine name: rest_api_authentication
Date: 2026-September-23
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Affected versions: <3.2.0
CVE IDs: CVE-2026-96385
Description: 
This module enables you to add an extra authentication layer to the API.

The module does not sufficiently validate authentication requirements for all
API requests, which can result in an access bypass vulnerability.

Solution: 
Install the latest version:

* Upgrade to REST & JSON API Authentication 3.2.0 [3].

Reported By: 
* Drew Webber (mcdruid) [4] of the Drupal Security Team

Fixed By: 
* Drew Webber (mcdruid) [5] of the Drupal Security Team
* purva_shende [6]

Coordinated By: 
* Swan Kalata (akalata) [7] of the Drupal Security Team
* Heine Deelstra (heine) [8] of the Drupal Security Team
* Drew Webber (mcdruid) [9] of the Drupal Security Team
* Juraj Nemec (poker10) [10] of the Drupal Security Team
* Jess (xjm) [11] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [12]

[1] https://www.drupal.org/project/rest_api_authentication
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/rest_api_authentication/releases/3.2.0
[4] https://www.drupal.org/u/mcdruid
[5] https://www.drupal.org/u/mcdruid
[6] https://www.drupal.org/u/purva_shende
[7] https://www.drupal.org/u/akalata
[8] https://www.drupal.org/u/heine
[9] https://www.drupal.org/u/mcdruid
[10] https://www.drupal.org/u/poker10
[11] https://www.drupal.org/u/xjm
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3616061

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] REST & JSON API Authentication for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2026-182, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang