Drupal Security Advisories Cover Information Disclosure, Access Bypass and Cross-Site Scripting

Drupal security graphic shows multiple project cards with warning symbols flowing through the Drupal logo into patched project cards with green checks. Text reads "SECURITY" "Security Patches Spread Across the Drupal Project Space" "Multiple contrib fixes one urgent maintenance check" "Follow us on" "https://www.thedroptimes.com/"

Security advisories published on 26 August 2026 covered 14 Drupal contributed projects in a batch of 15 notices. The Drupal Security Team rated 14 of the advisories Moderately Critical, while the advisory for Blazy was rated Less Critical. Disable Login Page was the only project to receive two advisories in the batch.

The batch includes flaws that can expose information, bypass access controls or enable cross-site scripting. Several can expose information to anonymous visitors under the configurations described in the advisories, including an exposed token in DXPR Builder, field values returned through Data field, and rendered block content exposed by Digital Signage Framework. Unlike the unsupported-project advisories issued on 19 August, the 26 August batch provides patched releases or supported upgrade paths.

Three advisories received the batch's highest risk score of 14/25. LDAP / Active Directory Integration does not sufficiently sanitise user-supplied input before incorporating it into LDAP search filters, allowing an attacker to discover information they should not normally access; Drupal.org marks exploit availability as Proof. DXPR Builder's affected 2.x branch can expose its token through drupalSettings to anonymous visitors when artificial intelligence features are enabled, while Address Suggestion can allow cross-site scripting through malicious suggestion data returned by a configured provider.

Entity API does not correctly apply access controls to collection endpoints when it is used with Drupal's JSON:API module. Data field can return field values for entities an anonymous visitor cannot otherwise view, including unpublished content. Entity PDF can serve a PDF without checking entity view access, while Digital Signage Framework can return rendered block content without confirming that the requester is a signage device or that the block is intended for display.

Disable Login Page received two separate access-bypass advisories. One advisory concerns insufficient restrictions on repeated attempts to guess the secret key used to reach the login form, while the second concerns cached login-page responses remaining accessible after restrictions are enabled. Content Moderation Notifications also received an access-bypass advisory because a permission allowing users to configure Twig-based email templates was not marked as restricted.

Commerce CyberSource does not correctly verify the integrity of data returned by the payment provider in its Secure Acceptance Hosted Checkout integration. Drupal.org says a timing attack could cause a site to register that payment was received when it was not. The issue affects only the Secure Acceptance Hosted Checkout gateway integration. CAPTCHA Protected Page can allow an unauthenticated visitor or automated bot to forge a verification cookie and bypass CAPTCHA checks.

Slick Carousel and Monster Menus received cross-site scripting advisories, while Blazy received the batch's only Less Critical advisory for an entity-access bypass. Drupal.org notes that Slick's vulnerability had already been fixed in 8.x-2.1, although that version was not marked as a security release at the time; maintainers now support only the 3.0.x branch. The Blazy issue can allow users with access to a Blazy-enabled text format to render certain fields from entities they are not permitted to view.

Drupal site teams should compare installed versions against the 26 August advisories and apply the applicable security releases or supported branch updates. LDAP / Active Directory Integration 2.2.1, Entity API 8.x-1.8 and DXPR Builder 2.8.1 are among the corrective releases identified by Drupal.org. The remediation path contrasts with the 16 unsupported contributed projects previously covered by The DropTimes, where Drupal's published response was to uninstall affected projects rather than install a fix.

References

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Upcoming Events