Date: 
2026-August-26
Vulnerability: 
Access bypass
Affected versions: 
<3.9.0
CVE IDs: 
CVE-2026-81161
Description: 

The module provides a permission that allows users to configure email templates containing Twig code. This permission was not marked as restricted.

A site administrator might inadvertently grant this permission to less-trusted users. This would allow those users to execute Twig within email templates, and to gain access to functionality and information intended only for highly trusted administrators.

Solution: 

Install the latest version:

  • If you use Content Moderation Notifications, upgrade to version 8.x-3.9.
  • Review roles to ensure only trusted roles have access to the "administer content moderation notifications" permission.

changed.

Reported By: 
Coordinated By: