Intel

AIKIDO-2026-704786

drupal/unpublished_node_permissions is vulnerable to Access Bypass

Access BypassCVE-2026-84920 Published Today

95

Critical Risk

This Affects:

PHPdrupal/unpublished_node_permissions
0.0.1 - 1.7.0
Fixed in 1.8.0
Are you affected? Scan for Free

TL;DR

An access control vulnerability in the module can bypass existing access restrictions by granting view access to published content, potentially exposing content that should otherwise be restricted.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/unpublished_node_permissions is vulnerable to Access Bypass in versions 0.0.1 - 1.7.0.

How to fix this

Upgrade the drupal/unpublished_node_permissions library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform