View online: https://www.drupal.org/sa-contrib-2026-099 Project: Quick Tabs [1] Date: 2026-August-12 Security risk: *Moderately critical* 13 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon [2] Vulnerability: Access bypass Affected versions: <4.3.1 CVE IDs: CVE-2026-73477 Description: This module enables you to display content in tabs, where each tab renders a block, a node, a view, or another Quick Tabs instance. The module did not correctly enforce access when rendering node and block tabs. It treated a neutral access result as a grant for node tabs and block plugins, and performed no access check for reusable custom blocks. Content that should have been denied was therefore rendered — for example, an unpublished node or unpublished reusable custom block could be shown to users without permission to view it. The access bypass is mitigated by the fact that affected content is selected by a user with the “administer quicktabs” permission when the tab is configured, so an attacker cannot choose which content is exposed. Solution: Install the latest version: * If you use the Quick Tabs module for Drupal, upgrade to Quick Tabs 4.3.1 [3] Reported By: * Joël Pittet (joelpittet) [4] Fixed By: * Joël Pittet (joelpittet) [5] Coordinated By: * Swan Kalata (akalata) [6] of the Drupal Security Team * Neil Drumm (drumm) [7] of the Drupal Security Team * Greg Knaddison (greggles) [8] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [9] [1] https://www.drupal.org/project/quicktabs [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/quicktabs/releases/4.3.1 [4] https://www.drupal.org/u/joelpittet [5] https://www.drupal.org/u/joelpittet [6] https://www.drupal.org/u/akalata [7] https://www.drupal.org/u/drumm [8] https://www.drupal.org/u/greggles [9] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....