SA-CONTRIB-2026-121: Critical severity drupal/ai_translate vulnerability
This module enables you to automatically translate entities. The module doesn't sufficiently check access on the entity to be translated, related fields or referenced entities when performing an AI translation on an entity or when those fields / entities have a different access level than the parent entity. This permission bypass is only applicable to the translate operation - no unwarranted read or update access is granted to the affected entities
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/ai_translateto a version that resolves this vulnerability.Fixed in 1.3.2Fixed in 1.4.1
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is applicable when performing an AI translation operation. The advisory does not specify any additional prerequisite permissions or authentication requirements.
Does this grant broader read or update access to protected entities?
No. The permission bypass is limited to the translate operation and does not grant unwarranted read or update access to affected entities.
Which content can be affected?
The affected scope includes the entity being translated, its related fields, and referenced entities when their access level differs from that of the parent entity.