SA-CONTRIB-2026-194: Critical severity drupal/entity_reference_manager vulnerability
Entity Reference Manager is an advanced administrative module for Drupal that allows site administrators to identify, analyze, and replace entity references across the system. The module does not sufficiently restrict access to all entity management operations. Users who can view content can access the entity merge functionality and delete arbitrary nodes, taxonomy terms, or media entities.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/entity_reference_managerto a version that resolves this vulnerability.Fixed in 1.0.3
Event History
Frequently Asked Questions
Which users are exposed to this issue?
Users who can view content can access the entity merge functionality. This access can be used to delete arbitrary nodes, taxonomy terms, or media entities.
What can an attacker do through the vulnerable functionality?
An attacker with content-viewing access can use entity merge functionality to delete arbitrary nodes, taxonomy terms, or media entities.