Project: 
Project machine name: 
smart_content
Date: 
2026-September-23
Vulnerability: 
Access bypass
Affected versions: 
<3.2.1
CVE IDs: 
CVE-2026-96386
Description: 

This module enables you to personalize content for anonymous and authenticated users by showing different blocks to visitors based on client-side conditions.

The Smart Content Block submodule doesn't sufficiently check block access when it renders the blocks of a "Display Blocks" reaction through the module's AJAX endpoint.

This vulnerability is mitigated by the fact that a site must have placed a block whose access is restricted to certain users inside a Display Blocks reaction. Sites that only use Views blocks in reactions are not affected, because Views re-checks access when the view is executed.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: