View online: https://www.drupal.org/sa-contrib-2026-190 Project: Smart Content [1] Project machine name: smart_content Date: 2026-September-23 Security risk: *Moderately critical* 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All [2] Vulnerability: Access bypass Affected versions: <3.2.1 CVE IDs: CVE-2026-96386 Description: This module enables you to personalize content for anonymous and authenticated users by showing different blocks to visitors based on client-side conditions. The Smart Content Block submodule doesn't sufficiently check block access when it renders the blocks of a "Display Blocks" reaction through the module's AJAX endpoint. This vulnerability is mitigated by the fact that a site must have placed a block whose access is restricted to certain users inside a Display Blocks reaction. Sites that only use Views blocks in reactions are not affected, because Views re-checks access when the view is executed. Solution: Install the latest version: * Upgrade to Smart Content 3.2.1 [3]. Reported By: * Tin Nguyen Huu (s4m0y3d) [4] Fixed By: * Michael Lander (michaellander) [5] * Tin Nguyen Huu (s4m0y3d) [6] Coordinated By: * Swan Kalata (akalata) [7] of the Drupal Security Team * Greg Knaddison (greggles) [8] of the Drupal Security Team * Jess (xjm) [9] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [10] [1] https://www.drupal.org/project/smart_content [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/smart_content/releases/3.2.1 [4] https://www.drupal.org/u/s4m0y3d [5] https://www.drupal.org/u/michaellander [6] https://www.drupal.org/u/s4m0y3d [7] https://www.drupal.org/u/akalata [8] https://www.drupal.org/u/greggles [9] https://www.drupal.org/u/xjm [10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....