PT-2026-107770 · Packagist · Drupal/Xray Audit
CVE-2026-96389
·
Publicado
2026-10-07
·
Atualizado
2026-10-07
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
This module enables you to audit a Drupal site by generating reports about its content, entities, display modes and configuration.
The module doesn't sufficiently check entity access when rendering an entity through the display-mode example route. This allows an attacker to view unpublished or otherwise access-restricted content.
This vulnerability is mitigated by the fact that field-level access is still enforced, so fields that are themselves access-restricted (for example a user's email or password hash) are not disclosed.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Drupal/Xray Audit