PT-2026-66339 · Drupal+2 · Token Content Access+2

·

CVE-2026-18259

·

Published

2026-07-29

·

Updated

2026-08-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Token Content Access versions 0.0.0 through 3.1.2
Description An observable timing discrepancy exists in the Token Content Access module, which allows site administrators to grant content access via access tokens. The module fails to sufficiently protect the comparison of access tokens, enabling a persistent attacker to perform a timing attack—a method of guessing secret data by measuring how long a system takes to respond—to discover a valid token and bypass access restrictions. Exploitation requires the attacker to know the URL of the protected content and accurately measure timing differences in the responses.
Recommendations Update Token Content Access to a version later than 3.1.2.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18259
DRUPAL-CONTRIB-2026-090

Affected Products

Token Content Access
Drupal/Tca
Tca