DRUPAL-CONTRIB-2026-099

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/quicktabs/DRUPAL-CONTRIB-2026-099.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-099
Aliases
  • CVE-2026-73477
Published
2026-08-12T17:56:54Z
Modified
2026-08-12T19:45:03.462198204Z
Summary
[none]
Details

This module enables you to display content in tabs, where each tab renders a block, a node, a view, or another Quick Tabs instance.

The module did not correctly enforce access when rendering node and block tabs. It treated a neutral access result as a grant for node tabs and block plugins, and performed no access check for reusable custom blocks. Content that should have been denied was therefore rendered — for example, an unpublished node or unpublished reusable custom block could be shown to users without permission to view it.

The access bypass is mitigated by the fact that affected content is selected by a user with the “administer quicktabs” permission when the tab is configured, so an attacker cannot choose which content is exposed.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/quicktabs

Package

Name
drupal/quicktabs
Purl
pkg:composer/drupal/quicktabs?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.1
Database specific
Show details
{
    "constraint": "<4.3.1"
}

Database specific

source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/quicktabs/DRUPAL-CONTRIB-2026-099.json"
affected_versions
"<4.3.1"