Project: 
Date: 
2026-September-02
Vulnerability: 
Access Bypass
Affected versions: 
<1.3.2 || >=1.4.0 <1.4.1
CVE IDs: 
CVE-2026-84913
Description: 

This module enables you to automatically translate entities.

The module doesn't sufficiently check access on the entity to be translated, related fields or referenced entities when performing an AI translation on an entity or when those fields / entities have a different access level than the parent entity. This permission bypass is only applicable to the translate operation - no unwarranted read or update access is granted to the affected entities

Solution: 

Install the latest version:

Coordinated By: