Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Editoria11y Accessibility Checker - Moderately critical - Access bypass - SA-CONTRIB-2026-185

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Editoria11y Accessibility Checker - Moderately critical - Access bypass - SA-CONTRIB-2026-185


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Editoria11y Accessibility Checker - Moderately critical - Access bypass - SA-CONTRIB-2026-185
  • Date: Wed, 23 Sep 2026 17:18:32 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Da1SkBAs; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=p0hk0QFq; arc=none smtp.remote-ip=54.240.27.115
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org A6FF743C57
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org 2E40E6087A
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790186900; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=IsH8kV69fIQLjXB4grXbUpLBqW3I2JtqNIcXxZYAKpY=; b=lI6+6wc+yr4QpBAga90FRqqjm7ByiYXh3oIlW9Hl8mXJTIYfSdZ22plUuX96iFu9BlCb xzKY7YKKwPhh0s6OwCakOGDgTV9/gBodBfp1nmA5hrOQV4oMvJTjfP9+QMwNTa3eIXAph oRAJnljK+lLY1xVGLx/M5a2agN4N74h2irrOd/Q8gN1p8PM7W9bnlRRhP+EFppwrkGH+q HBtuDCHgsUyACdN0V/Rm816+qV8CsG/2VIWIwIdn4Hl+KivaWr3oMDWBY6zH5W8DFK9YR 0rigJjxP72DZ78l6SR9Mudb+f3h803MBc6WxUslpZrv4NRssg5ML0EKSoseQCPiD2qw==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790183913; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=bp3O9j3QfjUoCy9jRTFBzinNMJgbyAjCL8e7eVKloZI=; b=RK10sN4dx7g2xac/SSqOt3rj6iXrhPr2DSz7oYV3XBG4H/eimFmzF3Sw+BbrOfauFDfd getSQgTOHOLPSbGiaeJBRqbR1u2rHgzH722KGpCVU/r6KgcmRb+Bg2b1HLMdNatARBcXN rWcODOc+qIV3BacVRa4dMKMswMym654tTND0fyKjAXCipId7OdljmHj7iqyW8mCR3O2+Z ReUcjTCIQhOWvUi6qp1YAUxnEPyQAjVfGOlwGzCCz1fF3MkhAW5yoThGPRb2TJofPCfUk VgJxegTdlOTNDz1rkkPrZq1e6TlqY1HV1iR99t0GkLBzoMKW51SnthSPA6Srki5C9Tg==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790186900; b=PrR4ui5FCjLO57L/bX8JmMhju2UdGS/5z9RVeSEnLIqVVDdtJKcge6SBRBInLwn4Fwjn 4HlShRQGa0fkttEqCrJWreSrqDIK2kPQ00YlyggcIk9c3uQf/qusqhrIElAcxffO4A7lV 7upSfCMy/CDhvc5k3emYqc0mQRKafeYaJ63t9R+6iYSs58M8mO/oXco+Y1mCSrCalqfoZ h0jH+YSa6y+4i9ET8ScBwyT5RzqfvISQe2KbwYwQfs8Mojfpmt3pIinH3twhDwsJT6YYu helj0ER61oZ5SAgYemMds5JPSN8XFuQUNwuReJGAsyA9/kSSiIM8NAVngJmay1t89xg==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790183913; b=N+cWwyCMCLtVZ6KmfeBOEQ5Oknew6c7xpRQr7P9gZ6vH2Aj8upDZD0i2DmNJpbYs42tE NsMydIidXpQ6AupxpXXiRNishem0Ot3PXw3IPLRbX80vP97qBUQWjPbiQqWHEf6PxvR4+ q6B86LCkck2azSPokf+3SHXXUU1S4rIuZYoiLig1IWtKDDYYfLHUqpRzqZFNFDqgcZK/n 5zYLllyMNi0ZoITdSapq7IcAqsWuwOBJzIvUbMBXeCyGqiUZNrG3Wnh3RdXnvIjPqrRk0 9eDaVOIpe48pP3zN0XmPl+QqA5YgkQdNSqg+oRhL50O9t8t+qSb0qZWedAGJc+Sq/Aw==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/O7PDEFA2AYSSXHOZYYMUGKTBYW5MKFZ5/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=G4hPBKhM; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Da1SkBAs; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=p0hk0QFq; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-185

Project: Editoria11y Accessibility Checker [1]
Project machine name: editoria11y
Date: 2026-September-23
Security risk: *Moderately critical* 11 ∕ 25
AC:Basic/A:User/CI:None/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Affected versions: <2.2.23 || >=3.0.0 <3.0.9
CVE IDs: CVE-2026-96390
Description: 
This module runs a client-side accessibility checker that automatically
reports results to dashboard views over an API.

The module incorrectly described a permission as a "view" permission when it
grants edit and delete access to module data, resulting in a potential access
bypass.

Solution: 
If you use the Editoria11y module, update the module and *review
permissions*.

* If you use the Editoria11y module version 2.2.x, upgrade to editoria11y
2.2.23 [3].
* If you use the Editoria11y module version 3.0.x, upgrade to editoria11y
3.0.9 [4].

*Review permissions:* Make sure anonymous or untrusted authenticated users
have not been given permission to use the checker. The permission is labeled
as:

* /View Editoria11y checker/ up to and including 2.2.22/3.0.8, and
* /Run Editoria11y checker and report results/ with 2.2.23/3.0.9.

Reported By: 
* Maksim Hayder (tr_jan) [5]

Fixed By: 
* Brian Osborne (bkosborne) [6]
* John Jameson (itmaybejj) [7]
* Jason Partyka (partyka) [8]

Coordinated By: 
* Swan Kalata (akalata) [9] of the Drupal Security Team
* Greg Knaddison (greggles) [10] of the Drupal Security Team
* Jess (xjm) [11] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [12]

[1] https://www.drupal.org/project/editoria11y
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/editoria11y/releases/2.2.23
[4] https://www.drupal.org/project/editoria11y/releases/3.0.9
[5] https://www.drupal.org/u/tr_jan
[6] https://www.drupal.org/u/bkosborne
[7] https://www.drupal.org/u/itmaybejj
[8] https://www.drupal.org/u/partyka
[9] https://www.drupal.org/u/akalata
[10] https://www.drupal.org/u/greggles
[11] https://www.drupal.org/u/xjm
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3623684

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Editoria11y Accessibility Checker - Moderately critical - Access bypass - SA-CONTRIB-2026-185, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang