Date: 
2026-March-04
Vulnerability: 
Access bypass
Affected versions: 
<1.2.0
CVE IDs: 
CVE-2026-3525
Description: 

This module moves files to and from private storage depending on the access of its owning entities.
The module does not sufficiently incorporate the results of hook_file_download when a custom or contrib module implements that hook leading to access bypass.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: