SA-CONTRIB-2026-182: Critical severity drupal/rest_api_authentication vulnerability
Published Sep 23, 2026
·Updated
This module enables you to add an extra authentication layer to the API. The module does not sufficiently validate authentication requirements for all API requests, which can result in an access bypass vulnerability.
Credit
Drew Webber (mcdruid)(the Drupal Security Team)
Affected Software
1 affected componentFixes available
drupal/rest_api_authentication<3.2.0
3.2.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/rest_api_authenticationto a version that resolves this vulnerability.Fixed in 3.2.0 - Compensating control
Add an extra authentication layer to the API to protect against access bypass caused by insufficient authentication validation.
Event History
Sep 23, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which component should teams inventory and prioritize for remediation?
The affected software is the Drupal rest_api_authentication module.
2
Does the advisory provide affected or fixed version information?
No affected version range or fixed release is provided in the available data.