Junglewise Threat Intelligence

CVE-2026-81269: Drupal Data field missing authorization in JSON endpoint

CVE-2026-81269 · Severity: medium · CVSS 5.3 · Published 2026-09-02

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Drupal Data field module is a plugin that stores and exposes structured custom field data through JSON endpoints. A missing authorization check in the JSON endpoint allows unauthenticated users to bypass access controls and view sensitive field values, including unpublished content they should not be able to access.

Technical details

The Data field module fails to properly check user permissions when returning field values through its JSON API endpoint. This is an authorization bypass vulnerability affecting the module's REST/JSON exposure layer. An unauthenticated attacker can directly query the endpoint to retrieve field data from entities (nodes, users, taxonomy terms, etc.) they do not have permission to view, including unpublished content. No authentication or user interaction is required; the vulnerability is exploitable by sending HTTP requests to the JSON endpoint. The fix is available in version 2.0.13, which adds appropriate access control checks.

Affected products

  • Drupal Data field < 2.0.13

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: patched: Version 2.0.13 released with fix

References

Related threats