CVE-2026-8491: Node View Permissions - Moderately critical - Access bypass - SA-CONTRIB-2026-034
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing.
This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal Node View Permissionsto a version that resolves this vulnerability.Fixed in 1.7.0 - Upgrade
Upgrade
Drupal Node View Permissionsto a version that resolves this vulnerability.Fixed in 2.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8491?
CVE-2026-8491 has a moderately critical severity due to an access bypass issue.
How do I fix CVE-2026-8491?
To fix CVE-2026-8491, upgrade Node View Permissions to version 1.7.0 or 2.0.1 or later.
What versions of Node View Permissions are affected by CVE-2026-8491?
CVE-2026-8491 affects Node View Permissions versions from 0.0.0 before 1.7.0 and from 2.0.0 before 2.0.1.
What type of vulnerability is CVE-2026-8491?
CVE-2026-8491 is classified as an access bypass vulnerability related to improper checks.
Is there a workaround for CVE-2026-8491?
There are no specific workarounds for CVE-2026-8491; updating to a secure version is recommended.