Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190
  • Date: Wed, 23 Sep 2026 17:23:38 +0000
  • Arc-authentication-results: i=2; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="AIO32dv/"; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=ZDuRjQ63; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="AIO32dv/"; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=ZDuRjQ63; arc=none smtp.remote-ip=54.240.27.123
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org D985770DE5
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org D261860890
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790187232; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=kSUgsgVabVzrWXTVqeV59UyhZ456Be/nxd+FRudm9+Q=; b=aTRqrz4KHWyL+vpNq9Jo7eSss8Cvvo9d4/vc9k8lW1LxoFsVq+csue9aC505YSyZi0eV Jx6hTznZ+RJcs8XVlLYY3X5o32FYRv9YmGU+wfS8kFsvQW+77HcUuL6IvVGL+t/CHG2Rf wRFkZTo2vcjhyoL2A1cFruGJFLcnxlFaIOkNavkXbGs5OTHnOC2KmYFPnE7wp9ICWrHk4 VvNXk7G+USWO6iZna8csKitra4wzLOCL498ZBGe4k96Fa1Tz1Hps3c87DZXMS1EZ+ghng QKVETuLO+08a71gybKn7ZVfNGRbiXhoUj92zOsoniKt/9dG6WwriqwDtH+2H83UJAOw==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790184219; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=bRH9RW2ZxxMSMqwRtRKquQEkZUvkAQQ39vjD4SpCkE4=; b=lz8b/XjYUSXB5xvhVMNbMzfKi04hsXnuJuw8tTlR37T6BT6uQB71T4/EqFEf1lBHtoiQ /3Kln7ycx6LdxeMnbOqo2pjzK51lgRGcAIsYtygIu5icZp8mf+jcrq4NTcdynH2T2/LCa Z5voNXe94vUvVbiNjYV03O2SpeTYvkyOHgDPaBaPf9oCYT2wCJ4dFagu1lMDG6R1KEmv1 qesk/ocuqSS3s6cLPQTHWHuDEo3ZBOIVivyiYkb/yRmCtImVvyDiJqhiwey9pBr4oCoOE EcqYxWzPWgJ7K2KTXPdwaz70AqfA9/4jdMS2xO4pnkHaf1pzWQ0yTB0RhTfnYKQgSiA==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790187232; b=DddJzjy1z9pY+PQRLiAEcpn65wyfDd1vRWZumpAM7OaAskQfqmKYtIHU1merN4y8D2pP BL/n1jPWEaAP1ZKiZ9WIDa2m2OWUQRNgU8Me/dOz80hI1i/x0oa0oOI4rS6zK7z2TH09H vOodAvNaoiytmd7oBaY5Eb7Cf1P0QbwOFzrMMwzi8zJXhTONjWs704FAVX+Jz2pTS7x+v L+J8SkPS3XUHmctMQj0JLDvYM6QrSKHPcaGuCTMoyzoW/lPSfCcWC9eKRuId5YaAx/lZW KEq+mT6sHr0+st5IuHc1P4SO0MSuPcBKAoBSsYR+l5/waYsdWWLkI8v4I8u2H2tQfGQ==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790184219; b=UGT3KjIINpHpJyw624oP+/5/nREKRpsXJcY0kFGHMJeLfXwbgXaeHzMIwbKf7s+yjTjl XsXSfzZbmVQeXbWmXlxkOLC1PQq3d5ekO5wjGUp6bJpiL9+JORmnQd0clz6x67dBXLSjV nYL4t5U1U3puHsSYfnzE/AQQiUslwLzLsp/urMWy0wN0AB9RtHsIUTxw4pbKsmRa+6h/6 Qnhm3f1EbotAyDpwoKEWYVkoxx9FEPVN3N0UZYq1CjcvumdaUwsHVaebMyALXkgHfBFAK SQ54kfyQa3HFE1FsBKzruXv/OzbrwxORcY2GBfibPKGujiS0/9ZQA6dVRmh3VDOEOWw==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/6HEFEWB7IRSBSSDVPKLVHKKY7VCHQZ4E/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b="EUaE4G/Y"; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="AIO32dv/"; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=ZDuRjQ63; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.136 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-190

Project: Smart Content [1]
Project machine name: smart_content
Date: 2026-September-23
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All [2]
Vulnerability: Access bypass

Affected versions: <3.2.1
CVE IDs: CVE-2026-96386
Description: 
This module enables you to personalize content for anonymous and
authenticated users by showing different blocks to visitors based on
client-side conditions.

The Smart Content Block submodule doesn't sufficiently check block access
when it renders the blocks of a "Display Blocks" reaction through the
module's AJAX endpoint.

This vulnerability is mitigated by the fact that a site must have placed a
block whose access is restricted to certain users inside a Display Blocks
reaction. Sites that only use Views blocks in reactions are not affected,
because Views re-checks access when the view is executed.

Solution: 
Install the latest version:

* Upgrade to Smart Content 3.2.1 [3].

Reported By: 
* Tin Nguyen Huu (s4m0y3d) [4]

Fixed By: 
* Michael Lander (michaellander) [5]
* Tin Nguyen Huu (s4m0y3d) [6]

Coordinated By: 
* Swan Kalata (akalata) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Jess (xjm) [9] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [10]

[1] https://www.drupal.org/project/smart_content
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/smart_content/releases/3.2.1
[4] https://www.drupal.org/u/s4m0y3d
[5] https://www.drupal.org/u/michaellander
[6] https://www.drupal.org/u/s4m0y3d
[7] https://www.drupal.org/u/akalata
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/xjm
[10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3623060

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang