View online: https://www.drupal.org/sa-contrib-2026-040 Project: TacJS [1] Date: 2026-June-03 Security risk: *Moderately critical* 11 ∕ 25 AC:Basic/A:User/CI:None/II:Some/E:Theoretical/TD:All [2] Vulnerability: Improper Access Control Affected versions: <6.8 CVE IDs: CVE-2026-49977 Description: This module enables sites to comply with the European cookie law using tarteaucitron.js. The module doesn't sufficiently filter user-supplied markup inside of content leading to an attacker being able to delete arbitrary cookies. This vulnerability is mitigated by the fact that an attacker needs to be able to insert specific data attributes in the page. Solution: Install the latest version: * If you use tacjs 8.x-6.x, upgrade to tacjs 8.x-6.8 [3] Reported By: * Pierre Rudloff (prudloff) [4] of the Drupal Security Team Fixed By: * Pierre Rudloff (prudloff) [5] of the Drupal Security Team Coordinated By: * Greg Knaddison (greggles) [6] of the Drupal Security Team * Pierre Rudloff (prudloff) [7] of the Drupal Security Team Security issue: https://git.drupalcode.org/security/185107-tacjs-security/-/work_items/1 [8] ------------------------------------------------------------------------------ Contribution record [9] [1] https://www.drupal.org/project/tacjs [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/tacjs/releases/8.x-6.8 [4] https://www.drupal.org/u/prudloff [5] https://www.drupal.org/u/prudloff [6] https://www.drupal.org/u/greggles [7] https://www.drupal.org/u/prudloff [8] https://git.drupalcode.org/security/185107-tacjs-security/-/work_items/1 [9] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....