SA-CONTRIB-2026-128: Critical severity drupal/symfony_mailer_log vulnerability

Published Sep 2, 2026
·
Updated

This module enables you to log the emails sent by Mailer Plus as content entities, so they can be reviewed at Reports > Mail log. The module doesn't sufficiently redact the content of the emails it logs. Account related emails are stored with their one-time login links intact, so any user who can view the log can obtain a one-time login link for any account, including user 1, and use it to log in as that account. This vulnerability is mitigated by the fact that an attacker must have a role with the permission View Drupal Symfony Mailer log entries, which in earlier releases was not marked as a restricted permission.

Credit

Sven Decabooter (svendecabooter)

Affected Software

1 affected componentFixes available
drupal/symfony_mailer_log<1.2.7
1.2.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade drupal/symfony_mailer_log to a version that resolves this vulnerability.

    Fixed in 1.2.7
  2. Compensating control

    Ensure the role permission "View Drupal Symfony Mailer log entries" is restricted (marked as a restricted permission in earlier releases), so only trusted users can view Mailer Plus email log entries at Reports > Mail log.

Event History

Sep 2, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software

Child vulnerabilities

Contains the following vulnerabilities.

Frequently Asked Questions

1

Who is exposed to this issue?

Any site using this module where a role can view Drupal Symfony Mailer log entries is exposed. That permission allows the role holder to access logged account-related emails containing intact one-time login links.

2

What access does an attacker need to exploit it?

An attacker needs a role with the View Drupal Symfony Mailer log entries permission. They can then obtain a one-time login link for any account, including user 1, from the mail log and use it to log in as that account.

3

Are default permissions a concern?

Earlier releases did not mark the View Drupal Symfony Mailer log entries permission as restricted. Review all roles assigned this permission, especially non-administrative roles that may have received it without recognizing its account-takeover impact.

4

What can be done if patching is not immediately possible?

Remove the View Drupal Symfony Mailer log entries permission from all roles that do not strictly require access to the log. Limit access to trusted administrators because log viewers can retrieve one-time login links for any account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203