DRUPAL-CONTRIB-2026-006

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/canvas/DRUPAL-CONTRIB-2026-006.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-006
Aliases
  • CVE-2026-1553
Published
2026-01-28T17:28:31Z
Modified
2026-01-28T18:41:17.216739Z
Summary
[none]
Details

This Drupal Canvas module is a new visual page builder for Drupal. You can create reusable components that match your design system, drag them onto a page, edit content in place, preview changes across multiple pages, and undo mistakes with ease.

The module doesn't sufficiently validate access to Canvas Pages when they are unpublished.

This vulnerability is mitigated by the fact that Canvas Pages don't have content moderation enabled by default, and they must be unpublished after being released, and archiving is not a feature provided by the module yet.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/canvas

Package

Name
drupal/canvas
Purl
pkg:composer/drupal/canvas

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.4
Database specific
{
    "constraint": "<1.0.4"
}

Database specific

source

"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/canvas/DRUPAL-CONTRIB-2026-006.json"

affected_versions

"<1.0.4"