SA-CONTRIB-2026-202: Critical severity drupal/gutenberg vulnerability
Published Oct 7, 2026
·Updated
This module provides a new UI experience for node editing using the Gutenberg Editor library. The module does not sufficiently check entity access in several editor endpoints. This vulnerability is mitigated by the fact that an attacker must have a role with the “use gutenberg” permission.
Credit
Tommaso Gregori (p1s1o), Drew Webber (mcdruid)(the Drupal Security Team)
Affected Software
1 affected componentFixes available
drupal/gutenberg<3.0.7, <8.x-2.15
3.0.78.x-2.15
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/gutenbergto a version that resolves this vulnerability.Fixed in 3.0.7Fixed in 8.x-2.15
Event History
Oct 7, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software