Drupal Security Team Publishes 26 Contrib Advisories, Led by Highly Critical Block AJAX Flaw
Published on 7 October 2026, a Drupal Security Team advisory identifies a highly critical PHP object injection flaw in Block AJAX. The vulnerability can lead to remote code execution on sites with Layout Builder enabled or another block plugin that handles the supplied data unsafely. Versions below 3.0.2 are affected, and the advisory instructs sites to update to 3.0.2.
The flaw is one of 26 contributed-project advisories published that day across 25 projects. The batch contains one highly critical, seven critical, 17 moderately critical and one less critical notice. Authenticator Login Plus accounts for two advisories. Several remedies also require configuration changes, database updates, cache clears or other follow-up work after the package itself is updated.
Block AJAX Carries the Highest Severity
Block AJAX's 3.0.2 release notes state that added Twig Tweak support introduced the issue and has been reverted. After updating, the route supports only blocks stored as configuration entities and placed through Structure > Block layout. Loading blocks from a plugin ID and supplied configuration, including the affected drupal_block() pattern, is no longer supported. The release notes direct affected implementations to a placed-block workaround.
Critical Advisories Include Unsupported Projects and Access-Control Failures
For ECA Helper and Orphans Media, the prescribed action is uninstalling the modules. Both projects have known security issues that their maintainers have not fixed, and the Security Team has marked them unsupported. The ECA Helper notice applies to eca_helper; it does not establish a vulnerability in the main ECA project.
A critical access-control flaw in Entity Reference Manager exposes destructive operations to users who can view content. Those users can reach merge functionality and delete arbitrary nodes, taxonomy terms or media entities. Version 1.0.3 fixes the issue.
Two other critical access-control notices concern route restrictions and account configuration. Restrict route by IP fails to enforce restrictions on a subset of dynamic routes, with impact dependent on how the site uses the module. Affected branches require 1.3.1 or 2.0.1. Actstream does not sufficiently check whether someone editing its configuration route owns the account or administers users; its corrective releases are 2.0.1 and 2.1.1.
Two authentication notices for Authenticator Login Plus (2FA) affect versions below 1.0.1. The critical issue allows Drupal core's one-time login link to bypass the second factor, but an attacker must possess a valid link for the victim's account. A separate moderately critical issue can permit password-only login despite site-wide 2FA enforcement. Version 1.0.1 fixes both vulnerabilities.
The critical MathJax: LaTeX for Drupal advisory requires an update to 4.1.2 and a check of Drupal's status report. The module ships library configurations that do not escape JavaScript within formatted TeX. If the status report warns that safe mode is disabled, the configuration could not be corrected automatically and requires a manual change following the advisory's instructions.
Some Updates Need Additional Remediation
After updating Authenticator Login Plus, users with 2FA enabled must provide their verification code when using a one-time login link. Users who previously disabled 2FA will be prompted to configure it again at their next login. Administrators can instead re-enable 2FA from the admin overview so that a user retains an existing authenticator. The release notes require clearing caches and state that no database updates are needed.
For Menu Link Attributes, updating to 8.x-1.8 must be followed by database updates. These remove unsafe attribute definitions and clear the render cache. The cross-site scripting issue requires an unsafe container attribute previously configured by someone with the restricted administration permission, plus an attacker with permissions to administer menus and use menu link attributes. The default configuration is unaffected.
The less critical Examples for Developers notice instructs sites to uninstall email_example immediately, then update to 4.0.7. The submodule can send illegitimate emails to arbitrary addresses and is being removed until a version demonstrating security best practices is available. Developers who copied the example into a module or custom code must review that code separately.
Moderately Critical Notices Cover Access and Information Disclosure
Missing entity-access checks affect several editor and administrative interfaces. Gutenberg requires 8.x-2.15 or 3.0.7 for affected editor endpoints, with exploitation requiring the use gutenberg permission. SmartLinker AI requires 1.0.3 because its internal-link search returns results without respecting entity access; an attacker must have permission to use that feature on a text format. Inline Entity Form Dialog, fixed in 1.0.6, relies on access administration pages without checking create or update access to the entity itself.
The Xray Audit display-mode example route can expose unpublished or otherwise restricted content, although field-level access remains enforced. Its corrective releases are 1.6.3, 2.0.4 and 3.1.1. DKAN requires 4.0.4 or 4.1.5 for insufficient access checks on datastore endpoints. The DKAN issue affects sites that withhold access content permission from anonymous users.
Other disclosure notices depend on narrower configurations. Permissions by Term requires 3.1.41 where Permission mode, a deleted taxonomy-term reference and JSON:API access coincide. Easy Breadcrumb requires 2.0.11 where parent hierarchy display is enabled and includes an unpublished parent term. Freelinking, fixed in 4.0.3, can reveal page titles from privately accessible external URLs when an attacker can use a text format configured to crawl them.
The Two Factor Authentication - TFA / Passwordless Login notice concerns disclosure of the stored miniOrange customer API key to unauthenticated users through a headless login endpoint. Headless 2FA must have been enabled by someone with the restricted permission for that feature. The corrective releases are 5.4.1 and 5.5.2.
Template Injection, XSS, CSRF and Resource-Use Issues Round Out the Batch
Template injection notices cover Linked Field, fixed in 8.x-1.8, and Inline Formatter Field, fixed in 4.2.0. Linked Field requires permission to create or edit content in an affected field and can expose sensitive configuration depending on installed Twig extensions. Inline Formatter Field can allow users to render protected data or execute unsafe Twig commands.
Cross-site scripting fixes include Leaflet 10.4.13 and Country 2.1.3 or 2.2.1. Leaflet's issue requires permission to create or edit content used in a map. Country's autocomplete issue requires additional modules or custom code and does not occur with the module alone.
The Advanced Filesystem cross-site request forgery issue requires the Backup submodule to be enabled and is fixed in 1.0.28. Views Share, fixed in 2.0.1, can execute resource-intensive views without displaying their data, potentially affecting performance when an attacker knows the view and display IDs.
The advisories do not establish observed exploitation or the number of vulnerable installations. Site maintainers should compare installed versions and enabled functionality against the individual notices rather than infer exposure from project usage figures alone.
References
-
Block AJAX - Highly critical - PHP object injection - SA-CONTRIB-2026-192, Drupal Security Team (7 October 2026)
-
-
-
-
Entity Reference Manager (Merge entities) - Critical - Access bypass - SA-CONTRIB-2026-194, Drupal Security Team (7 October 2026)
-
Restrict route by IP - Critical - Access bypass - SA-CONTRIB-2026-216, Drupal Security Team (7 October 2026)
-
-
Authenticator Login Plus (2FA) - Critical - Improper authentication - SA-CONTRIB-2026-197, Drupal Security Team (7 October 2026)
-
Authenticator Login Plus (2FA) - Moderately critical - Improper authentication - SA-CONTRIB-2026-201, Drupal Security Team (7 October 2026)
-
-
MathJax: LaTeX for Drupal - Critical - Cross site scripting - SA-CONTRIB-2026-195, Drupal Security Team (7 October 2026)
-
Menu Link Attributes - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-209, Drupal Security Team (7 October 2026)
-
Examples for Developers - Less critical - Allocation of resources without limits or throttling - SA-CONTRIB-2026-215, Drupal Security Team (7 October 2026)
-
Gutenberg - Moderately critical - Access bypass - SA-CONTRIB-2026-202, Drupal Security Team (7 October 2026)
-
SmartLinker AI - Moderately critical - Information disclosure - SA-CONTRIB-2026-210, Drupal Security Team (7 October 2026)
-
Inline Entity Form Dialog - Moderately critical - Access bypass - SA-CONTRIB-2026-199, Drupal Security Team (7 October 2026)
-
Xray Audit - Moderately critical - Access bypass - SA-CONTRIB-2026-206, Drupal Security Team (7 October 2026)
-
DKAN - Moderately critical - Access bypass - SA-CONTRIB-2026-208, Drupal Security Team (7 October 2026)
-
Permissions by Term - Moderately critical - Information disclosure - SA-CONTRIB-2026-214, Drupal Security Team (7 October 2026)
-
Easy Breadcrumb - Moderately critical - Information disclosure - SA-CONTRIB-2026-212, Drupal Security Team (7 October 2026)
-
Freelinking - Moderately critical - Information Disclosure - SA-CONTRIB-2026-213, Drupal Security Team (7 October 2026)
-
Two Factor Authentication - TFA / Passwordless Login - Moderately critical - Information disclosure - SA-CONTRIB-2026-207, Drupal Security Team (7 October 2026)
-
Linked Field - Moderately critical - Server-side template injection - SA-CONTRIB-2026-200, Drupal Security Team (7 October 2026)
-
Inline Formatter Field - Moderately critical - Server-side template injection - SA-CONTRIB-2026-203, Drupal Security Team (7 October 2026)
-
Leaflet - Moderately critical - Cross site scripting - SA-CONTRIB-2026-204, Drupal Security Team (7 October 2026)
-
Country - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-211, Drupal Security Team (7 October 2026)
-
Advanced Filesystem - Moderately critical - Cross-Site Request Forgery - SA-CONTRIB-2026-217, Drupal Security Team (7 October 2026)
-
Views Share - Moderately critical - Access bypass - SA-CONTRIB-2026-205, Drupal Security Team (7 October 2026)
