Executive brief
The Tealium iQ Tag Management module for Drupal, which helps businesses manage marketing and tracking tags, contains a critical security flaw. An attacker with permissions to edit content could inject malicious code into the system, potentially leading to full site takeover or data theft. This risk is significantly higher if the site has certain non-default data interface settings (JSON:API) enabled.
Technical details
The Tealium iQ Tag Management module for Drupal is vulnerable to PHP Object Injection (CWE-915/CWE-502) because it stores certain data as PHP-serialized strings without sufficient validation. An attacker with content editing permissions can write malicious serialized data directly to a tealiumiq field. When this data is subsequently unserialized by the application, it can lead to arbitrary code execution or unauthorized data access. The vulnerability is most easily exploited if the core JSON:API module is enabled with write operations permitted, or if another mechanism exists to bypass standard form validation. The issue is resolved in version 8.x-2.4.
Affected products
- Drupal Tealium iQ Tag Management 0.0.0 to 2.3.9
Timeline
- 2026-06-24: other: Project briefly marked unsupported by Drupal Security Team
- 2026-06-25: patched: Version 8.x-2.4 released
- 2026-06-26: advisory: Drupal security advisory SA-CONTRIB-2026-064 published
- 2026-07-10: disclosed: CVE-2026-13244 published to NVD