Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096
View online: https://www.drupal.org/sa-contrib-2026-096 Project: Diff [1] Date: 2026-August-12 Security risk: *Moderately critical* 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All [2] Vulnerability: Access bypass Affected versions: <2.0.1 || >=2.1.0 <2.1.1 CVE IDs: CVE-2026-73478 Description: This module enables you to view the differences between revisions on any entity type. The module doesn't sufficiently restrict access to non-node entity revision diffs. This vulnerability is mitigated by the fact that an attacker must have a role with the permission view the entity. Solution: Install the latest version: * If you use the Diff module, upgrade to Diff 2.1.1 [3] or Diff 2.0.1 [4] Reported By: * Alexei Rayu (alexrayu) [5] Fixed By: * Adam Bramley (acbramley) [6] * Derek Wright (dww) [7] * Lee Rowlands (larowlan) [8] of the Drupal Security Team Coordinated By: * Swan Kalata (akalata) [9] of the Drupal Security Team * Greg Knaddison (greggles) [10] of the Drupal Security Team * Lee Rowlands (larowlan) [11] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [12] [1] https://www.drupal.org/project/diff [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/diff/releases/2.1.1 [4] https://www.drupal.org/project/diff/releases/2.0.1 [5] https://www.drupal.org/u/alexrayu [6] https://www.drupal.org/u/acbramley [7] https://www.drupal.org/u/dww [8] https://www.drupal.org/u/larowlan [9] https://www.drupal.org/u/akalata [10] https://www.drupal.org/u/greggles [11] https://www.drupal.org/u/larowlan [12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org