View online: https://www.drupal.org/sa-contrib-2026-039 Project: LocalGov Workflows [1] Date: 2026-June-03 Security risk: *Moderately critical* 14 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:Default [2] Vulnerability: Information disclosure Affected versions: <1.6.0 CVE IDs: CVE-2026-10768 Description: This module configures default editorial workflows for LocalGov Drupal content types. It provides a Drupal content moderation workflow, a content approvals dashboard, content scheduling and content preview. The module doesn't sufficiently restrict access to a view of Service Contacts at which exposes the names and content items assigned to each Service Contact. Solution: Install the latest version: * If you use the LocalGov Workflows module for Drupal, upgrade to LocalGov Workflows 1.6.0 [3] Reported By: * Maria Young (maria.y) [4] Fixed By: * Finn Lewis (finn lewis) [5] * Rupert Jabelman (rupertj) [6] Coordinated By: * Greg Knaddison (greggles) [7] of the Drupal Security Team * Dave Long (longwave) [8] of the Drupal Security Team * Juraj Nemec (poker10) [9] of the Drupal Security Team Security issue: https://git.drupalcode.org/security/185130-localgov_workflows-security/-/work_it… [10] ------------------------------------------------------------------------------ Contribution record [11] [1] https://www.drupal.org/project/localgov_workflows [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/localgov_workflows/releases/1.6.0 [4] https://www.drupal.org/u/mariay-0 [5] https://www.drupal.org/u/finn-lewis [6] https://www.drupal.org/u/rupertj [7] https://www.drupal.org/u/greggles [8] https://www.drupal.org/u/longwave [9] https://www.drupal.org/u/poker10 [10] https://git.drupalcode.org/security/185130-localgov_workflows-security/-/wor... [11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....