Project machine name: 
unpublished_node_permissions
Date: 
2026-September-02
Vulnerability: 
Access bypass
Affected versions: 
<1.8.0
CVE IDs: 
CVE-2026-84920
Description: 

This module creates permissions per node content type to control access to unpublished content.

The module has allowed view access for published content, overriding other access mechanisms that might have been in place.

Solution: 

Install the latest version:

Coordinated By: