Intel

AIKIDO-2026-699042

drupal/diff is vulnerable to Access Bypass

Access BypassCVE-2026-73478 Published 3 days ago

50

Medium Risk

This Affects:

PHPdrupal/diff
0.0.1 - 2.0.0
Fixed in 2.0.1
2.1.0 - 2.1.0
Fixed in 2.1.1
Are you affected? Scan for Free

TL;DR

The Diff module does not sufficiently restrict access to non-node entity revision diffs, allowing users who can view an entity to access revision differences they should not be able to see. This vulnerability is mitigated by the fact that an attacker must have a role with permission to view the entity.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/diff is vulnerable to Access Bypass in versions 0.0.1 - 2.0.0 and 2.1.0 - 2.1.0.

How to fix this

Upgrade the drupal/diff module to the patch version.