SA-CONTRIB-2026-208: Critical severity drupal/dkan vulnerability
The DKAN module enables organizations and individuals to build open data portals in Drupal. The DKAN datastore imports tabular data files into database tables and exposes them for querying with a JSON API. The module does not correctly check access for all of its endpoints, leading to a potential access bypass. The vulnerability is mitigated by the fact that it is only impactful for sites that do not give "access content" permission to the anonymous role.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/dkanto a version that resolves this vulnerability.Fixed in 4.1.5Fixed in 4.0.4 - Configuration
Grant the anonymous role the "access content" permission to mitigate the vulnerability.
Drupal anonymous role access content permission = enabled