Taxonomy Term Glossary - Critical - Access bypass - SA-CONTRIB-2026-152
View online: https://www.drupal.org/sa-contrib-2026-152 Project: Taxonomy Term Glossary [1] Date: 2026-September-09 Security risk: *Critical* 15 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:All [2] Vulnerability: Access bypass Affected versions: <4.6.0 CVE IDs: CVE-2026-87954 Description: This module adds automatic highlighting of taxonomy terms in content. The module doesn't sufficiently check access on taxonomy terms. As a result, anonymous users can view any of the site's taxonomy terms at the module's JSON endpoint, including taxonomy terms that are unpublished or otherwise restricted. Solution: Install the latest version: * If you use the Taxonomy Term Glossary module, upgrade to term_glossary 4.6.0 [3]. The 4.4.x and 4.5.x branches are no longer supported. Reported By: * Hemant Gupta (guptahemant) [4] * Marcus Johansson (marcus_johansson) [5] * Serhii Checheniev (serhii-che) [6] Fixed By: * Frank Mably (mably) [7] Coordinated By: * Greg Knaddison (greggles) [8] of the Drupal Security Team * Juraj Nemec (poker10) [9] of the Drupal Security Team * Jess (xjm) [10] of the Drupal Security Team * Swan Kalata (akalata) [11] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [12] [1] https://www.drupal.org/project/term_glossary [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/term_glossary/releases/4.6.0 [4] https://www.drupal.org/u/guptahemant [5] https://www.drupal.org/u/marcus_johansson [6] https://www.drupal.org/u/serhii-che [7] https://www.drupal.org/u/mably [8] https://www.drupal.org/u/greggles [9] https://www.drupal.org/u/poker10 [10] https://www.drupal.org/u/xjm [11] https://www.drupal.org/u/akalata [12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org