Vulnerability DRUPAL-CONTRIB-2026-206
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
11 hours ago
October 07, 2026 at 04:30 PM UTC
No summary available
Details
This module enables you to audit a Drupal site by generating reports about its content, entities, display modes and configuration.
The module doesn't sufficiently check entity access when rendering an entity through the display-mode example route. This allows an attacker to view unpublished or otherwise access-restricted content.
This vulnerability is mitigated by the fact that field-level access is still enforced, so fields that are themselves access-restricted (for example a user's email or password hash) are not disclosed.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Impacted packages
Timeline
Published
11 hours ago
October 07, 2026 at 04:30 PM UTC
Last Modified
7 hours ago
October 07, 2026 at 08:15 PM UTC