SA-CONTRIB-2026-198: Critical severity drupal/actstream vulnerability
Actstream (short for Activity Stream) aggregates a user's activity from external services (RSS feeds, etc.) into per-user activity stream entities. The configuration route does not sufficiently check that the user editing it is the account owner (or a user administrator) leading to an access bypass vulnerability.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/actstreamto a version that resolves this vulnerability.Fixed in 2.1.1Fixed in 2.0.1
Event History
Frequently Asked Questions
Which users should be allowed to make these configuration changes?
Only the account owner or a user administrator should be authorized to edit the affected configuration.
What access is needed for exploitation?
An attacker would need access to the configuration route. The vulnerability is that this route does not adequately verify that the editor owns the account or is a user administrator.
Are affected versions or detection indicators available?
No affected version range, fixed version, or specific compromise indicators are provided in the available data.