Executive brief
The Flag attendance field module for Drupal, which allows sites to track attendance for events or classes, contains a critical security flaw. An attacker with permission to edit content could inject malicious code into the system, potentially leading to full site takeover or data theft. This risk is significantly higher if the site has certain non-default API settings enabled.
Technical details
A PHP Object Injection vulnerability (CWE-915/CWE-502) exists in the Flag attendance field module because it stores data as PHP-serialized strings and allows malicious data to be written directly to the field in certain configurations. An attacker with permissions to edit a content entity containing this field can trigger the vulnerability when the data is subsequently unserialized. The attack is most feasible if the core JSON:API module is enabled with all CRUD operations permitted, or if another mechanism exists to modify field values directly. Successful exploitation can lead to remote code execution (RCE) depending on the available POP chains in the environment. The issue is fixed in version 8.x-1.2.
Affected products
- Drupal Flag attendance field 0.0.0 to 1.2
Timeline
- 2026-06-17: patched: Version 8.x-1.2 released
- 2026-06-17: advisory: Drupal security advisory SA-CONTRIB-2026-049 published
- 2026-07-10: disclosed: CVE-2026-55809 published to NVD