Node View Permissions - Moderately critical - Access bypass - SA-CONTRIB-2026-034
View online: https://www.drupal.org/sa-contrib-2026-034 Project: Node View Permissions [1] Date: 2026-May-13 Security risk: *Moderately critical* 11 ∕ 25 AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:Default [2] Vulnerability: Access bypass Affected versions: <1.7.0 || >=2.0.0 <2.0.1 CVE IDs: CVE-2026-8491 Description: Node view permissions module enables permissions "View own content" and "View any content" for each content type on permissions page The module doesn't sufficiently handle the case where a user is cancelled and their content is reassigned to the anonymous user. This vulnerability is mitigated by the fact that only private contents where anonymous should not have view access are affected, and only if a node was reassigned to the anonymous user. Solution: Install the latest version: * If you use the Node View Permissions module version 2.0.0. or prior, upgrade to 2.0.1. [3] * If you use the Node View Permissions module version 8.x-1.6. or prior, upgrade to 8.x-1.7. [4] Reported By: * Adam Shepherd (adamps) [5] Fixed By: * Bálint Nagy (nagy.balint) [6] Coordinated By: * Greg Knaddison (greggles) [7] of the Drupal Security Team * Juraj Nemec (poker10) [8] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [9] [1] https://www.drupal.org/project/node_view_permissions [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/node_view_permissions/releases/2.0.1 [4] https://www.drupal.org/project/node_view_permissions/releases/8.x-1.7 [5] https://www.drupal.org/u/adamps [6] https://www.drupal.org/u/nagybalint [7] https://www.drupal.org/u/greggles [8] https://www.drupal.org/u/poker10 [9] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org