DRUPAL-CONTRIB-2026-022

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/ajax_dashboard/DRUPAL-CONTRIB-2026-022.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-022
Aliases
  • CVE-2026-3527
Published
2026-03-04T17:57:58Z
Modified
2026-03-04T19:02:25.504389Z
Summary
[none]
Details

AJAX Dashboard: Entity Dashboards enables you to create configurable dashboards attached to entities which include AJAX-reloading of a main content area based on inputs from a configurable set of buttons.

The module doesn't sufficiently check access on the dashboard configuration route. Unauthorized users could access the entity dashboard configuration page and either enable or disable dashboards. The affected administration page does not permit editing the configurations of the dashboards themselves.

The vulnerability is mitigated by the fact that the AJAX Dashboard Entity Dashboard submodule must be enabled.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/ajax_dashboard

Package

Name
drupal/ajax_dashboard
Purl
pkg:composer/drupal/ajax_dashboard

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.0
Database specific
{
    "constraint": "<3.1.0"
}

Database specific

source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/ajax_dashboard/DRUPAL-CONTRIB-2026-022.json"
affected_versions
"<3.1.0"