DRUPAL-CONTRIB-2026-183

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/stop_admin/DRUPAL-CONTRIB-2026-183.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-183
Aliases
  • CVE-2026-96387
Published
2026-09-23T17:11:27Z
Modified
2026-09-23T19:15:05Z
Summary
[none]
Details

This module enables sites to block access for the administrative user account (user 1) or users with the administrator role.

The module does not sufficiently enforce these access restrictions across all supported authentication mechanisms. As a result, a blocked administrative user may still be able to authenticate through certain alternative authentication methods.

This vulnerability is mitigated by the fact that an attacker must possess valid credentials for a user with the administrator role, and must authenticate using a less commonly used authentication mechanism.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/stop_admin

Package

Name
drupal/stop_admin
Purl
pkg:composer/drupal/stop_admin?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.6.0
Database specific
Show details
{
    "constraint":  ">=1.0 <1.6"
}

Database specific

affected_versions
">=1.0 <1.6"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/stop_admin/DRUPAL-CONTRIB-2026-183.json"