SA-CONTRIB-2026-132: Critical severity drupal/unpublished_node_permissions vulnerability
This module creates permissions per node content type to control access to unpublished content. The module has allowed view access for published content, overriding other access mechanisms that might have been in place.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/unpublished_node_permissionsto a version that resolves this vulnerability.Fixed in 8.x-1.8
Event History
Frequently Asked Questions
Which deployments are most likely to be affected?
Deployments using this module are at risk where other access-control mechanisms are intended to restrict viewing of published content. The module can allow view access to published content despite those other restrictions.
How can I assess whether my site is exposed?
Review whether the module is enabled and whether published content is subject to access restrictions imposed by other mechanisms. If so, verify that published content cannot be viewed by users who should be denied access.