Junglewise Threat Intelligence

CVE-2026-81161: Drupal Content Moderation Notifications permission bypass with Twig code execution

CVE-2026-81161 · Severity: low · CVSS 3.3 · Published 2026-09-02

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

Drupal's Content Moderation Notifications module allows site administrators to configure email templates containing Twig code. A permission that was not marked as restricted could be granted to less-trusted users, enabling them to execute Twig code in templates and gain unauthorized access to admin-level functionality and data. This is a privilege escalation risk when administrators mistakenly grant powerful permissions to untrustworthy users.

Technical details

The vulnerability is a permission configuration issue where the "administer content moderation notifications" permission was not marked as restricted in Drupal's permission system. This permission allows users to configure email templates that contain Twig template code. An attacker with this permission can execute arbitrary Twig expressions, which provides access to sensitive admin functionality and data. The attack requires a site administrator to grant the unprotected permission to a less-trusted user. The fix is to upgrade to version 3.9.0 or later and audit role assignments to ensure only trusted administrators have the permission.

Affected products

  • Drupal Content Moderation Notifications before 3.9.0

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: patched: Version 3.9.0 released

References

Related threats