Intel

AIKIDO-2025-10520

drupal/config_pages is vulnerable to Access bypass

Access bypassCVE-2025-8361

60

Medium Risk

This Affects:

PHPdrupal/config_pages
1.0.0 - 2.17.0
Fixed in 2.18.0

TL;DR

Affected versions of this package are vulnerable to access bypass due to insufficient enforcement of access control checks. Specifically, the module fails to properly respect the hook_ENTITY_TYPE_access() permissions, allowing unauthorized users to access or manipulate entities they should not have permission to view or modify. This oversight can lead to unintended exposure of data or unauthorized operations.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/config_pages is vulnerable to Access bypass in versions 1.0.0 - 2.17.0.

How to fix this

Upgrade the drupal/config_pages library to the patch version.