Intel

AIKIDO-2026-10362

drupal/unpublished_node_permissions is vulnerable to Access Bypass

Access BypassCVE-2026-4933 Published Mar 16, 2026

92

Critical Risk

This Affects:

PHPdrupal/unpublished_node_permissions
1.0.0 - 1.6.0
Fixed in 1.7.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to access bypass: the module does not consistently control access for unpublished translated nodes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/unpublished_node_permissions is vulnerable to Access Bypass in versions 1.0.0 - 1.6.0.

How to fix this

Upgrade the drupal/unpublished_node_permissions library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform