SA-CONTRIB-2026-206: Critical severity drupal/xray_audit vulnerability
This module enables you to audit a Drupal site by generating reports about its content, entities, display modes and configuration. The module doesn't sufficiently check entity access when rendering an entity through the display-mode example route. This allows an attacker to view unpublished or otherwise access-restricted content. This vulnerability is mitigated by the fact that field-level access is still enforced, so fields that are themselves access-restricted (for example a user's email or password hash) are not disclosed.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/xray_auditto a version that resolves this vulnerability.Fixed in 3.1.1Fixed in 2.0.4Fixed in 1.6.3