DRUPAL-CONTRIB-2026-107

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/content_moderation_notifications/DRUPAL-CONTRIB-2026-107.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-107
Aliases
  • CVE-2026-81161
Published
2026-08-26T17:36:16Z
Modified
2026-08-26T22:30:03.839607288Z
Summary
[none]
Details

The module provides a permission that allows users to configure email templates containing Twig code. This permission was not marked as restricted.

A site administrator might inadvertently grant this permission to less-trusted users. This would allow those users to execute Twig within email templates, and to gain access to functionality and information intended only for highly trusted administrators.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/content_moderation_notifications

Package

Name
drupal/content_moderation_notifications
Purl
pkg:composer/drupal/content_moderation_notifications?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.0
Database specific
Show details
{
    "constraint": "<3.9.0"
}

Database specific

source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/content_moderation_notifications/DRUPAL-CONTRIB-2026-107.json"
affected_versions
"<3.9.0"