Drupal · Diff · CVE-2026-73478
**Name of the Vulnerable Software and Affected Versions**
Drupal Diff versions 0.0.0 through 2.0.1
Drupal Diff versions 2.1.0 through 2.1.1
**Description**
An incorrect authorization issue allows forceful browsing. The module does not sufficiently restrict access to non-node entity revision diffs. This requires the attacker to possess a role with permission to view the entity.
**Recommendations**
Update Drupal Diff versions 0.0.0 through 2.0.1 to a fixed version.
Update Drupal Diff versions 2.1.0 through 2.1.1 to a fixed version.