PT-2026-97676 · Packagist · Drupal/Smart Content

CVE-2026-96386

·

Published

2026-09-23

·

Updated

2026-09-23

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module enables you to personalize content for anonymous and authenticated users by showing different blocks to visitors based on client-side conditions.
The Smart Content Block submodule doesn't sufficiently check block access when it renders the blocks of a "Display Blocks" reaction through the module's AJAX endpoint.
This vulnerability is mitigated by the fact that a site must have placed a block whose access is restricted to certain users inside a Display Blocks reaction. Sites that only use Views blocks in reactions are not affected, because Views re-checks access when the view is executed.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-96386
DRUPAL-CONTRIB-2026-190

Affected Products

Drupal/Smart Content