Junglewise Threat Intelligence

CVE-2026-1553: DRUPAL-CONTRIB-2026-006 - This Drupal Canvas module is a new visual page builder for Drupal. You can create reusable components that match your design system, drag th

CVE-2026-1553 · Severity: info · Published 2026-01-28

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Canvas. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

This Drupal Canvas module is a new visual page builder for Drupal. You can create reusable components that match your design system, drag them onto a page, edit content in place, preview changes across multiple pages, and undo mistakes with ease.

The module doesn't sufficiently validate access to Canvas Pages when they are unpublished.

This vulnerability is mitigated by the fact that Canvas Pages don't have content moderation enabled by default, and they must be unpublished after being released, and archiving is not a feature provided by the module yet.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/canvas

Related threats