Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
View online: https://www.drupal.org/sa-core-2026-010 Project: Drupal core [1] Date: 2026-July-15 Security risk: *Moderately critical* 10 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon [2] Vulnerability: Information disclosure Affected versions: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 || 11.0.* || 11.1.* || 11.2.* CVE IDs: CVE-2026-15916 Description: The Image module allows you to define and configure image fields. The module doesn't sufficiently check access to image style derivatives when those files are served via a file stream other than private://. This vulnerability is mitigated by the fact that Drupal must be configured to use a contributed (non-core) file scheme to serve private derived images. Information disclosure issues like this one are not generally given security advisories (as described in PSA-2023-07-12) [3]). This fix is provided as a hardening. Contributed modules implementing custom stream wrappers may need to add similar hardenings. Solution: Install the latest version: *Drupal 11* * If you use Drupal 11.4.x, update to Drupal 11.4.4 [4]. * If you use Drupal 11.3.x, update to Drupal 11.3.14 [5]. * Drupal 11.2.x and below are end-of-life and do not receive security coverage. *Drupal 10* * If you use Drupal 10.6.x, update to Drupal 10.6.13 [6]. * Drupal 10.5.x and below are end-of-life and do not receive security coverage. Drupal 8 [7] and Drupal 9 [8] have both reached end-of-life. Reported By: * offensive-ai [9] Fixed By: * Benji Fisher (benjifisher) [10] of the Drupal Security Team * Kim Pepper (kim.pepper) [11] * Mohit Aghera (mohit_aghera) [12] Coordinated By: * Benji Fisher (benjifisher) [13] of the Drupal Security Team * catch (catch) [14] of the Drupal Security Team * Lee Rowlands (larowlan) [15] of the Drupal Security Team * Juraj Nemec (poker10) [16] of the Drupal Security Team * Jess (xjm) [17] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [18] [1] https://www.drupal.org/project/drupal [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/psa-2023-07-12 [4] https://www.drupal.org/project/drupal/releases/11.4.4 [5] https://www.drupal.org/project/drupal/releases/11.3.14 [6] https://www.drupal.org/project/drupal/releases/10.6.13 [7] https://www.drupal.org/psa-2021-06-29 [8] https://www.drupal.org/psa-2023-11-01 [9] https://www.drupal.org/u/offensive-ai [10] https://www.drupal.org/u/benjifisher [11] https://www.drupal.org/u/kimpepper [12] https://www.drupal.org/u/mohit_aghera [13] https://www.drupal.org/u/benjifisher [14] https://www.drupal.org/u/catch [15] https://www.drupal.org/u/larowlan [16] https://www.drupal.org/u/poker10 [17] https://www.drupal.org/u/xjm [18] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org