Project:
Project machine name:
jsonapi_role_accessDate:
2026-September-02
Vulnerability:
Access bypass
Affected versions:
<2.0.2
CVE IDs:
CVE-2026-84917
Description:
This module enables you to restrict access to JSON:API routes based on specific user roles.
The module doesn't sufficiently enforce access controls under scenarios where a request mimics an XMLHttpRequest.
Solution:
Install the latest version:
- If you use the Jsonapi Role Access module, upgrade to Jsonapi Role Access 2.0.2
Reported By:
- Drew Webber (mcdruid) of the Drupal Security Team
Coordinated By:
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team