Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Stop administrator login - Moderately critical - Access bypass - SA-CONTRIB-2026-183

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Stop administrator login - Moderately critical - Access bypass - SA-CONTRIB-2026-183


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Stop administrator login - Moderately critical - Access bypass - SA-CONTRIB-2026-183
  • Date: Wed, 23 Sep 2026 17:11:28 +0000
  • Arc-authentication-results: i=2; smtp1.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=WQZRncT7; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=DtCLE0Ji; arc=none smtp.remote-ip=54.240.27.116
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 36CB6874E9
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org A8C1B40122
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790186750; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=7JU41Kf5Tlc7xjPp3GG94YCfOEv5bFb/nElRIHhepX8=; b=drnAucNWpjQG/u8PmZjxj9gWokDHVB8zVkMI5IscQFICoympBWTz50PtVU1znWhIbOHh gqH9PX+3Pg2Cp5BXZv+IVREHeTfbY5kg+5FSsqz6Gf1227VXU5IaYzY2TK4GOocNBbSGv QxAKYKKBcTA8FzoNA8sZXr82WMb20hB+zQOkASZ8ju9yZL2gxdOGs2ERu1UdH/jkPpK6x P8MVv77jK9FJ1PYLzgGvqd4u4h1IRYlNN39UQ82id5NLmG2y2y+QnkTf0KgUDe/R9Quwr uaS2g46aFZ5rZLF1yPbDj9qAdtDkmNPJIkLhrDHcls7aLFtUHAcg1sh8IIeBlLGID6Q==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790183489; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=3s9sox+5qlHXge+SzFSy64XJ8CjlqLFG4qGCSP7XJoU=; b=lUoWa2zfxb/ihaRR9HWm1H3Rw1jt/lx0JyDTJOpj84CXyRYU23Cxfa2g+pN9EzUgTmk2 kHabT4MHXH5d/dazmiM8OZYQ430V0wJcqoayQbqCfEcYBK7BAYk9xm6B7xS1/A0VOygGE Goy+L07H6R9gTf3MmAa5FgjoxO4Tjm7giFOIVv32TsoGIMHn1P/i5fV9fheV8W/x8IhZY /iV+hHEZOIKElrDPZxgMIptRs85UwxusHN6lTz7n9F2C6+jtY51pYUIpAynASPsByMuvf jz1BRDjUIqMXu1O2+au9Xv3lCHw5QuUBwzuxBe7HupufHDaes7yoe+NwNq6E8g+pnRw==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790186750; b=hXjE4UJ1ogcH3rFnDxdHuAXgvTOMxAEkqAURy7PNq/BPiqB2XHtFyTZOK0P54Xu65bV9 fBh9yRwY31+kn5GcBwHjmuffPm1kWgBa2EI50bjBqELw7VlQ0KZ+I/HG6DMpNoBBgdCKw +RN5e4XGV7RW20L6iur4pgugvsP/xaNeXoti201nfdDREQ5GANPiCFHAfpKEXRHpoZM85 42tdZoinVPijftSR7GaRTuXu4qzYK4F4fLyp+sM8f92gNMVpfHgb16ofOo663irb7sibn jOuAXmBD6BID8KyHPKkezYZdz48q/u/14aUwDJsM+2ZLBATs2SrdX2Het3htpJkNV8w==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790183489; b=mNyJd4AJram6OS39ostdNHO4q7KtdUW8OCCF5YlKBjJ7sOIOxhZxdD1mMl/lqYDlMsiD Z4j9tRlX82m69Q3LZr5T2ydf7qTPm/BTZ762H31mSUWJeg6K3+xpL+1DG7wpEAyqjrBl8 ylLSnBIAYoCqfZIUwfope6EoC9IGbkljYVoAtUu3e0ym6edlfGW6U0LEJurF4waPXxEoN Nfc77KCOSWIcpjk0i4tLsbgmSvyjDXYBVgbIGYZfPgGP8WBmpP2nDkLsy2h/4C93hCXvT WA2ZfQhZ42XEQi0rtuTfQIH28Xu9ky5md6lfWIBTLdxrukR3BJdwT+dhZlWghxqjKXg==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/CVV4IXLJKJZ524XS65Z4NQN6YESGTR3V/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=VmL8xg59; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=WQZRncT7; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=DtCLE0Ji; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-183

Project: Stop administrator login [1]
Project machine name: stop_admin
Date: 2026-September-23
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Affected versions: >=1.0 <1.6
CVE IDs: CVE-2026-96387
Description: 
This module enables sites to block access for the administrative user account
(user 1) or users with the administrator role.

The module does not sufficiently enforce these access restrictions across all
supported authentication mechanisms. As a result, a blocked administrative
user may still be able to authenticate through certain alternative
authentication methods.

This vulnerability is mitigated by the fact that an attacker must possess
valid credentials for a user with the administrator role, and must
authenticate using a less commonly used authentication mechanism.

Solution: 
Install the latest version:

* If you use the Stop Administrator Login module, upgrade to Stop
Administrator Login 8.x-1.6 [3]

Reported By: 
* Pierre Rudloff (prudloff) [4] of the Drupal Security Team

Fixed By: 
* Bram Driesen (bramdriesen) [5] of the Drupal Security Team

Coordinated By: 
* Swan Kalata (akalata) [6] of the Drupal Security Team
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Pierre Rudloff (prudloff) [10] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [11]

[1] https://www.drupal.org/project/stop_admin
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/stop_admin/releases/8.x-1.6
[4] https://www.drupal.org/u/prudloff
[5] https://www.drupal.org/u/bramdriesen
[6] https://www.drupal.org/u/akalata
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/prudloff
[11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3623229

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Stop administrator login - Moderately critical - Access bypass - SA-CONTRIB-2026-183, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang