Project: 
Date: 
2026-August-26
Vulnerability: 
Information disclosure
Affected versions: 
<2.0.13
CVE IDs: 
CVE-2026-81269
Description: 

This module enables you to store structured data in configurable fields and expose Data Field values through JSON endpoints.

The module doesn't sufficiently check access when returning Data Field values through its JSON endpoint. This may allow anonymous users to access field values belonging to entities they cannot otherwise view, including unpublished content.

Solution: 

Install the latest version:

Coordinated By: