Project machine name: 
term_glossary
Date: 
2026-September-09
Vulnerability: 
Access bypass
Affected versions: 
<4.6.0
CVE IDs: 
CVE-2026-87954
Description: 

This module adds automatic highlighting of taxonomy terms in content.

The module doesn't sufficiently check access on taxonomy terms. As a result, anonymous users can view any of the site's taxonomy terms at the module's JSON endpoint, including taxonomy terms that are unpublished or otherwise restricted.

Solution: 

Install the latest version:

The 4.4.x and 4.5.x branches are no longer supported.

Fixed By: 
Coordinated By: