Drupal Issues 16 Contributed-Project Advisories, Including Five Critical Flaws

Security graphic examining common patterns across a group of contributed project fixes. Text reads "SECURITY". "One Advisory Batch Many Ways Access Checks Failed". "A closer look at the patterns behind the latest contributed project fixes". Connected document cards and branching nodes visualize different access check paths and failures. "Follow us on". "https://www.thedroptimes.com/"

Site administrators have 16 new contributed-project security advisories to assess after the Drupal Security Team published its 2 September 2026 disclosure batch. Five are rated Critical and 11 Moderately Critical across 14 projects. Twelve concern access bypass and four concern cross-site scripting; no Drupal core advisory was issued.

The batch carries higher severity than the similarly large disclosure on 26 August 2026, when Drupal published 15 contributed-project advisories without a Critical rating. The change is severity rather than volume. The flaws involve account takeover, content and API access controls, private files and reusable login links. Reported project usage also ranges from a handful of sites to tens of thousands, but those figures do not show how many installations remain vulnerable.

Unpublished Node Permissions, reported on more than 4,000 sites, has a Critical 15/25 access bypass that can allow published content to be viewed despite another access mechanism denying it; 8.x-1.8 contains the fix. Jsonapi Role Access, with about 750 reported installations, is rated Critical at 16/25 because requests mimicking XMLHttpRequest can bypass configured JSON:API role restrictions. Version 2.0.2 fixes the issue.

Email Verification / SMS Verification / OTP Verification received two Critical 16/25 advisories. One concerns unauthenticated account takeover and the other unauthenticated reflected cross-site scripting; both are fixed in 8.x-2.4. Calculate Working Days also received a Critical advisory for insufficient restriction of its settings form, fixed in 2.0.3.

Mailer Plus Log requires more than installing its 1.2.7 release. Logged account emails could retain one-time login links, including links for user 1, so administrators must also run database updates to redact existing logs and review access to them. Media Library Importer, fixed in 2.1.6, could copy readable private files into Drupal's public files directory and publish them as Media entities.

Two Moderately Critical disclosures affect projects with much wider reported use. At the time of disclosure, Drupal.org reported PhotoSwipe on 15,667 sites and the AI project on 17,818 sites. PhotoSwipe has a 14/25 cross-site scripting flaw in dynamic captions that requires permission to enter HTML content; version 5.0.9 fixes it. The AI project received an access-bypass advisory for AI-assisted translation and a narrower cross-site scripting advisory involving legacy agent configurations. Affected AI branches should move to 1.3.13 or 1.4.8, although the project-wide usage count does not indicate how many sites use the affected functions.

The separate AI translate project received a related translation access-bypass advisory, fixed in 1.3.2 and 1.4.1. Monobank payment API failed to verify webhook signatures before processing payment-status callbacks and is fixed in 1.0.3. Advanced Search and Islandora received related advisories involving access checks on restricted blocks, while Component blocks received a cross-site scripting fix. Webform Submissions Delete also received an access-bypass fix, although its advisory notes that a separate PHP fatal error may prevent practical exploitation on Drupal 10 and later.

All 16 advisories record exploit availability as theoretical, meaning no public exploit code or documentation for developing an exploit is known. Drupal's 25-point security ratings come from its own risk-calculation system and should not be reported as CVSS scores. The concentration of access-control failures echoes earlier TDT coverage of the 12 August advisory batch, but the disclosures do not establish a single common Drupal defect. Corrective releases are available for every advisory in the 2 September batch.

References

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Upcoming Events