Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093
View online: https://www.drupal.org/sa-contrib-2026-093 Project: Edit in-place field [1] Date: 2026-August-05 Security risk: *Moderately critical* 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Access bypass Affected versions: <2.1.1 CVE IDs: CVE-2026-18985 Description: This module provides formatters to allow in-place editing in a View or other display (full content, teaser...). The module doesn't sufficiently check access when editing entities. A malicious user could craft requests to allow them to modify any field on any entity. This vulnerability is mitigated by the fact that an attacker must have a role with the permission "edit in place field editing permission". Solution: Install the latest version: * If you use the Edit in-place field module for Drupal, upgrade to 2.1.1 [3] Reported By: * Drew Webber (mcdruid) [4] of the Drupal Security Team Fixed By: * Bálint Nagy (nagy.balint) [5] Coordinated By: * Neil Drumm (drumm) [6] of the Drupal Security Team * Greg Knaddison (greggles) [7] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [8] [1] https://www.drupal.org/project/edit_in_place_field [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/edit_in_place_field/releases/2.1.1 [4] https://www.drupal.org/u/mcdruid [5] https://www.drupal.org/u/nagybalint [6] https://www.drupal.org/u/drumm [7] https://www.drupal.org/u/greggles [8] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org