SA-CONTRIB-2026-096: Critical severity drupal/diff vulnerability
This module enables you to view the differences between revisions on any entity type. The module doesn't sufficiently restrict access to non-node entity revision diffs. This vulnerability is mitigated by the fact that an attacker must have a role with the permission view the entity.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/diffto a version that resolves this vulnerability.Fixed in 2.1.1Fixed in 2.0.1
Event History
Frequently Asked Questions
What is the severity of SA-CONTRIB-2026-096?
The severity of SA-CONTRIB-2026-096 is rated as critical with a score of 9.
What does SA-CONTRIB-2026-096 vulnerability affect?
SA-CONTRIB-2026-096 affects the Drupal 'diff' module, allowing unauthorized viewing of entity revision differences.
How can I mitigate SA-CONTRIB-2026-096?
Mitigation for SA-CONTRIB-2026-096 involves ensuring that users have appropriate roles and permissions to view entity revisions.
How do I fix SA-CONTRIB-2026-096?
To fix SA-CONTRIB-2026-096, you should apply the latest patch or update provided for the 'diff' module in Drupal.
What needs to be done if I am using the 'diff' module in Drupal concerning SA-CONTRIB-2026-096?
If you are using the 'diff' module in Drupal, ensure that your user roles are properly configured and update the module to the latest version to address SA-CONTRIB-2026-096.