Junglewise Threat Intelligence

CVE-2026-96390: Drupal Editoria11y permission access bypass

CVE-2026-96390 · Severity: info · Published 2026-09-23

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

Editoria11y is a Drupal module that performs client-side accessibility checks and reports results to dashboard views. The module misclassified a permission as granting only view access when it actually grants edit and delete capabilities, allowing unauthorized users to modify or remove accessibility data. An attacker with access to the misnamed permission could bypass intended access controls and tamper with accessibility reports.

Technical details

A permission in the Editoria11y module was incorrectly labeled as a "view" permission despite granting edit and delete access to module data. This mislabeling can cause administrators to inadvertently grant broader privileges than intended when configuring user permissions. The vulnerability allows users with the permission to perform unauthorized modifications or deletions of accessibility checker data through an API.

Affected products

  • Drupal Editoria11y <2.2.23 or >=3.0.0, <3.0.9

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Versions 2.2.23 and 3.0.9 released with permission relabeling

References