REST & JSON API Authentication for Drupal - Moderately critical - Access bypass - SA-CONTRIB-2026-182
View online: https://www.drupal.org/sa-contrib-2026-182 Project: REST & JSON API Authentication for Drupal [1] Project machine name: rest_api_authentication Date: 2026-September-23 Security risk: *Moderately critical* 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:All [2] Vulnerability: Access bypass Affected versions: <3.2.0 CVE IDs: CVE-2026-96385 Description: This module enables you to add an extra authentication layer to the API. The module does not sufficiently validate authentication requirements for all API requests, which can result in an access bypass vulnerability. Solution: Install the latest version: * Upgrade to REST & JSON API Authentication 3.2.0 [3]. Reported By: * Drew Webber (mcdruid) [4] of the Drupal Security Team Fixed By: * Drew Webber (mcdruid) [5] of the Drupal Security Team * purva_shende [6] Coordinated By: * Swan Kalata (akalata) [7] of the Drupal Security Team * Heine Deelstra (heine) [8] of the Drupal Security Team * Drew Webber (mcdruid) [9] of the Drupal Security Team * Juraj Nemec (poker10) [10] of the Drupal Security Team * Jess (xjm) [11] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [12] [1] https://www.drupal.org/project/rest_api_authentication [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/rest_api_authentication/releases/3.2.0 [4] https://www.drupal.org/u/mcdruid [5] https://www.drupal.org/u/mcdruid [6] https://www.drupal.org/u/purva_shende [7] https://www.drupal.org/u/akalata [8] https://www.drupal.org/u/heine [9] https://www.drupal.org/u/mcdruid [10] https://www.drupal.org/u/poker10 [11] https://www.drupal.org/u/xjm [12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org