SA-CONTRIB-2026-099: Critical severity drupal/quicktabs vulnerability
This module enables you to display content in tabs, where each tab renders a block, a node, a view, or another Quick Tabs instance. The module did not correctly enforce access when rendering node and block tabs. It treated a neutral access result as a grant for node tabs and block plugins, and performed no access check for reusable custom blocks. Content that should have been denied was therefore rendered — for example, an unpublished node or unpublished reusable custom block could be shown to users without permission to view it. The access bypass is mitigated by the fact that affected content is selected by a user with the “administer quicktabs” permission when the tab is configured, so an attacker cannot choose which content is exposed.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/quicktabsto a version that resolves this vulnerability.Fixed in 4.3.1
Event History
Frequently Asked Questions
What is the severity of SA-CONTRIB-2026-099?
The severity of SA-CONTRIB-2026-099 is critical with a rating of 9.
What risk does SA-CONTRIB-2026-099 pose?
SA-CONTRIB-2026-099 carries a risk level of 42.
How do I fix SA-CONTRIB-2026-099?
To fix SA-CONTRIB-2026-099, you should update the Quick Tabs module to the latest version where the vulnerability has been addressed.
What vulnerabilities are associated with SA-CONTRIB-2026-099?
SA-CONTRIB-2026-099 involves improper access control for rendering node and block tabs.
Who is affected by SA-CONTRIB-2026-099?
Users of the Drupal Quick Tabs module are affected by SA-CONTRIB-2026-099.