DRUPAL-CONTRIB-2026-206

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/xray_audit/DRUPAL-CONTRIB-2026-206.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-206
Aliases
  • CVE-2026-96389
Published
2026-10-07T16:30:05Z
Modified
2026-10-07T20:15:08Z
Summary
[none]
Details

This module enables you to audit a Drupal site by generating reports about its content, entities, display modes and configuration.

The module doesn't sufficiently check entity access when rendering an entity through the display-mode example route. This allows an attacker to view unpublished or otherwise access-restricted content.

This vulnerability is mitigated by the fact that field-level access is still enforced, so fields that are themselves access-restricted (for example a user's email or password hash) are not disclosed.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/xray_audit

Package

Name
drupal/xray_audit
Purl
pkg:composer/drupal/xray_audit?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.6.3
Database specific
Show details
{
    "constraint": "<1.6.3"
}
Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.0.4
Database specific
Show details
{
    "constraint": ">=2.0.0 <2.0.4"
}
Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.1.1
Database specific
Show details
{
    "constraint": ">=3.0.0 <3.1.1"
}

Database specific

affected_versions
"<1.6.3 || >=2.0.0 <2.0.4 || >=3.0.0 <3.1.1"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/xray_audit/DRUPAL-CONTRIB-2026-206.json"