Drupal Issues 16 Contributed-Project Advisories, Including Five Critical Flaws
Site administrators have 16 new contributed-project security advisories to assess after the Drupal Security Team published its 2 September 2026 disclosure batch. Five are rated Critical and 11 Moderately Critical across 14 projects. Twelve concern access bypass and four concern cross-site scripting; no Drupal core advisory was issued.
The batch carries higher severity than the similarly large disclosure on 26 August 2026, when Drupal published 15 contributed-project advisories without a Critical rating. The change is severity rather than volume. The flaws involve account takeover, content and API access controls, private files and reusable login links. Reported project usage also ranges from a handful of sites to tens of thousands, but those figures do not show how many installations remain vulnerable.
Unpublished Node Permissions, reported on more than 4,000 sites, has a Critical 15/25 access bypass that can allow published content to be viewed despite another access mechanism denying it; 8.x-1.8 contains the fix. Jsonapi Role Access, with about 750 reported installations, is rated Critical at 16/25 because requests mimicking XMLHttpRequest can bypass configured JSON:API role restrictions. Version 2.0.2 fixes the issue.
Email Verification / SMS Verification / OTP Verification received two Critical 16/25 advisories. One concerns unauthenticated account takeover and the other unauthenticated reflected cross-site scripting; both are fixed in 8.x-2.4. Calculate Working Days also received a Critical advisory for insufficient restriction of its settings form, fixed in 2.0.3.
Mailer Plus Log requires more than installing its 1.2.7 release. Logged account emails could retain one-time login links, including links for user 1, so administrators must also run database updates to redact existing logs and review access to them. Media Library Importer, fixed in 2.1.6, could copy readable private files into Drupal's public files directory and publish them as Media entities.
Two Moderately Critical disclosures affect projects with much wider reported use. At the time of disclosure, Drupal.org reported PhotoSwipe on 15,667 sites and the AI project on 17,818 sites. PhotoSwipe has a 14/25 cross-site scripting flaw in dynamic captions that requires permission to enter HTML content; version 5.0.9 fixes it. The AI project received an access-bypass advisory for AI-assisted translation and a narrower cross-site scripting advisory involving legacy agent configurations. Affected AI branches should move to 1.3.13 or 1.4.8, although the project-wide usage count does not indicate how many sites use the affected functions.
The separate AI translate project received a related translation access-bypass advisory, fixed in 1.3.2 and 1.4.1. Monobank payment API failed to verify webhook signatures before processing payment-status callbacks and is fixed in 1.0.3. Advanced Search and Islandora received related advisories involving access checks on restricted blocks, while Component blocks received a cross-site scripting fix. Webform Submissions Delete also received an access-bypass fix, although its advisory notes that a separate PHP fatal error may prevent practical exploitation on Drupal 10 and later.
All 16 advisories record exploit availability as theoretical, meaning no public exploit code or documentation for developing an exploit is known. Drupal's 25-point security ratings come from its own risk-calculation system and should not be reported as CVSS scores. The concentration of access-control failures echoes earlier TDT coverage of the 12 August advisory batch, but the disclosures do not establish a single common Drupal defect. Corrective releases are available for every advisory in the 2 September batch.
References
-
Jsonapi Role Access - Critical - Access bypass - SA-CONTRIB-2026-127 (2 September 2026)
-
Calculate Working Days - Critical - Access bypass - SA-CONTRIB-2026-122 (2 September 2026)
-
Mailer Plus Log - Moderately critical - Access bypass - SA-CONTRIB-2026-128 (2 September 2026)
-
AI translate - Moderately critical - Access Bypass - SA-CONTRIB-2026-121 (2 September 2026)
-
Advanced Search - Moderately critical - Access bypass - SA-CONTRIB-2026-118 (2 September 2026)
-
Islandora - Moderately critical - Access bypass - SA-CONTRIB-2026-126 (2 September 2026)
