Drupal · Token Content Access · CVE-2026-18259
**Name of the Vulnerable Software and Affected Versions**
Token Content Access versions 0.0.0 through 3.1.2
**Description**
An observable timing discrepancy exists in the Token Content Access module, which allows site administrators to grant content access via access tokens. The module fails to sufficiently protect the comparison of access tokens, enabling a persistent attacker to perform a timing attack—a method of guessing secret data by measuring how long a system takes to respond—to discover a valid token and bypass access restrictions. Exploitation requires the attacker to know the URL of the protected content and accurately measure timing differences in the responses.
**Recommendations**
Update Token Content Access to a version later than 3.1.2.