Junglewise Threat Intelligence

CVE-2026-18986: Drupal Entity Browser stored XSS in tab titles

CVE-2026-18986 · Severity: medium · CVSS 4.8 · Published 2026-09-02

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

Drupal Entity Browser is a module that allows site administrators to select entities (such as media, files, or content) through a custom browsing interface. The module fails to properly sanitize tab titles, allowing an attacker with the ability to create or modify entities to inject malicious JavaScript that executes in the browsers of other users viewing the entity browser. This could lead to session hijacking, data theft, or defacement.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Drupal Entity Browser versions prior to 2.16.0, where tab titles are not sufficiently sanitized before output. The vulnerability is stored, meaning the malicious payload persists in the database and executes whenever a user views an entity browser displaying the affected tab. The attack requires an authenticated user with the ability to create or insert HTML with specific attributes in a location where an entity browser is displayed. The vulnerability was fixed in version 2.16.0; users should upgrade immediately.

Affected products

  • Drupal Entity Browser before 2.16.0

Timeline

  • 2026-08-05: disclosed
  • 2026-08-11: patched

References

Related threats