Drupal · Quick Tabs · CVE-2026-73477
**Name of the Vulnerable Software and Affected Versions**
Drupal Quick Tabs versions 0.0.0 through 4.3.1
**Description**
An incorrect authorization issue allows forceful browsing. The module fails to correctly enforce access when rendering node and block tabs by treating neutral access results as grants for node tabs and block plugins. Additionally, no access check is performed for reusable custom blocks. This allows users without proper permissions to view restricted content, such as unpublished nodes or unpublished reusable custom blocks. The risk is limited because the content exposed is pre-selected by a user with the `administer quicktabs` permission during configuration.
**Recommendations**
Update Drupal Quick Tabs to a version later than 4.3.1.