Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026-064

Date: 
2026-June-26
CVE IDs: 
CVE-2026-13244

The Tealium iQ Tag Management module provides Drupal integration with Tealium iQ.

tealiumiq stores some data as PHP-serialized strings. In some situations, malicious data can be written directly to the field. This can lead to an Object Injection vulnerability when the data are unserialized.

Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063

Date: 
2026-June-24
CVE IDs: 
CVE-2026-13243

The Salesforce Suite of modules integrates Drupal with Salesforce.

The Salesforce module does not properly validate the OAuth handshake during interactive authentication, allowing an attacker to hijack the authorization token and bind the site to an attacker's Salesforce account.

Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062

Date: 
2026-June-24
CVE IDs: 
CVE-2026-13242

Geolocation modules adds a field to store coordinates and provides supporting plumbing for views and other modules.

One of the provided views filters does not sufficiently sanitize values if exposed to user input resulting in a SQL injection vulnerability.

This vulnerability is mitigated by the fact that a view must exist, that uses the aforementioned filter and it is set to accept user input.

Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061

Date: 
2026-June-24
CVE IDs: 
CVE-2026-13241

The optional Paragraphs Library module allows the reuse of paragraphs in multiple places.
The module doesn't sufficiently restrict access to direct child paragraphs of library items through API endpoints.
This vulnerability is mitigated by the fact the paragraphs_library module must be in use and general write access to paragraphs through another module must be allowed.

Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060

Date: 
2026-June-24
CVE IDs: 
CVE-2026-13240

The optional Paragraphs Library module allows the reuse of paragraphs in multiple places.
The module doesn't sufficiently restrict access to unpublished library items in lists.
This vulnerability is mitigated by the fact the paragraphs_library module must be in use, and that an attacker must have access to a list of library items, such as a field with autocomplete suggestions or a view.

WissKI - Critical - Access bypass - SA-CONTRIB-2026-059

Date: 
2026-June-24
CVE IDs: 
CVE-2026-13239

The module adds support for the mirador viewer in WissKI and enables annotations on images via the mirador viewer.

It does not sufficiently check the submitted parameters via a route and writes these to the session object without further checks, which can lead to Access Bypass.

This vulnerability is mitigated by the fact that it is specific to the wisski_mirador submodule.

Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-CONTRIB-2026-058

Date: 
2026-June-24
CVE IDs: 
CVE-2026-13238

This module enables you to take payments through the Global Payments / Realex Hosted Payment Page (HPP), either via a lightbox iframe or via a full-page redirect.

When the gateway is configured with the redirect payment method, the module doesn't sufficiently verify the authenticity of the payment response returned by Global Payments.

The lightbox payment method validates the signature and is not affected, so sites that use the lightbox payment method are not affected.

AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057

Date: 
2026-June-24
CVE IDs: 
CVE-2026-13237

This module provides the entity type and runtime for Drupal AI Agents, enabling agents to use tools.

Under certain circumstances, the agent inherits deterministic parameters when invoking the same tool in one request, which can lead to information disclosure.

AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056

Date: 
2026-June-24
CVE IDs: 
CVE-2026-13236

This module provides the entity type and runtime for Drupal AI Agents, enabling agents to use tools.

The module does not sufficiently check the required permissions when a tool loads content entities.

This vulnerability is mitigated by the fact that an agent must be configured to use the affected tool, and an attacker must have access to that agent.

AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055

Date: 
2026-June-24
CVE IDs: 
CVE-2026-13235

This module enables you to utilize an agent to use Drupal core actions tools with bypassed access.

Certain Drupal core actions, exposed as agent tools did not have correct access validation, and some core actions were missing associated access-level definitions.

This vulnerability is mitigated by the fact that an attacker must have access to communicate with an affected agent, the site must be configured to expose the affected tools to non-privileged users.

Pages

Subscribe with RSS Subscribe to Security advisories