[CIVN-2026-0404] Multiple Vulnerabilities in Drupal Plugins

By Published On: August 11, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Drupal Plugins


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Drupal Entity Browser module versions prior to 8.x-2.16

Drupal Edit in-place field module versions prior to 2.1.1

Overview


Multiple vulnerabilities have been reported in Drupal contributed modules which may allow an attacker to bypass access controls and modify unauthorized content or execute stored cross-site scripting (XSS) attacks through insufficient input sanitization.


Target Audience:

Individuals and end-user organizations using Drupal Modules.


Risk Assessment:

High risk of unauthorized modification of Drupal entities and fields, access control bypass, and stored cross-site scripting attacks.


Impact Assessment:

Potential for unauthorized modification of content and fields, bypass of security restrictions, execution of malicious scripts in the context of affected users, and compromise of sensitive website functionality.


Description


Drupal is an open-source content management system (CMS) which allows individuals and organizations to create, manage and maintain websites and web applications.


These vulnerabilities exist in the Drupal modules due to insufficient access control checks when editing entities and improper sanitization of tab titles, resulting in unauthorized modification of entity fields and stored cross-site scripting (XSS).


Successful exploitation of these vulnerabilities could allow an attacker to bypass security restrictions, modify unauthorized Drupal content or fields, and perform stored cross-site scripting attacks against users of the affected system.


Solution


Apply appropriate updates as mentioned:

https://www.drupal.org/sa-contrib-2026-093


https://www.drupal.org/sa-contrib-2026-094



Vendor Information


Drupal

https://www.drupal.org/sa-contrib-2026-093

https://www.drupal.org/sa-contrib-2026-094


References


Drupal

https://www.drupal.org/sa-contrib-2026-093

https://www.drupal.org/sa-contrib-2026-094


CVE Name

CVE-2026-18985

CVE-2026-18986




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7KRQACgkQ3jCgcSdc

ys8ETw/+Kmb85tHSVf0CJxn4hTXH7XuiQYWvirHvtnJFXp3kEsqnpcw9TklCVee+

4A4XbmL9rLRIgrmxYf495+PuQcMBSDfVtaXCI8cXxlSZ3dd/jGrWHw3S8lLwvxNj

1uLxZaPphfN50FDf9HVtr000lNieLN2BHbrTffbGg+9DBeDUqETcZW0yazUFP9SN

zKISjjMoZeIF/Ig4gRZEGah7xnZ3z9jBepvemQYHW9tc6Np1iu1mPS9sQ9uMwWvh

UAJIpUvqUWRiWOPwFb3xeecpA0/a6eW33w7XWFQUI5BDnIb38XE66yp7Sr9DxBgo

9mdUVqOjKCRYSbKBq/cOxygOi/enAqFU7XqMYHCu9NUubYv+D9Vi6eufjz/0wroK

M0fHlw+1RPioYUNcyqhqfNn9Pdzoo6pU2ot4TxhI0HOc0k1Be2OnlY4y5adJI5R2

MxJCV1jsrHwfvJsW7b+KPxU7HXkvx/nc2HzMXd+RdRUou0YjIp30M8hsvcbyx8mU

bPy/fSXyrAN/GulV7b+tLfO2O9EGTxkw9bYVs4Vp6U0cZsjEYseru7XmUqIXPF+r

1/3rVdGBcfINvkKqGscRZacvq97QevgkTdP4JHMTCb4n6i1RP13XMu+2BawJ+JYw

nVX8wkwx4xYRs5heMC9kZNiWszgr4ulD/AOLBAeUAE9G2kj3BV0=

=Dc4c

—–END PGP SIGNATURE—–

Share this article