Project machine name: 
jsonapi_role_access
Date: 
2026-September-02
Vulnerability: 
Access bypass
Affected versions: 
<2.0.2
CVE IDs: 
CVE-2026-84917
Description: 

This module enables you to restrict access to JSON:API routes based on specific user roles.

The module doesn't sufficiently enforce access controls under scenarios where a request mimics an XMLHttpRequest.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: