Drupal security updates, in plain English

Week of 14 January 2026

Drupal publishes security updates on Wednesdays. This week there were 5, all for modules.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Critical: 1 update

Cyber Essentials expects a fix within 14 days. Do it this week.

Microsoft Entra ID SSO Login

Critical · 211 sites report using it · SA-CONTRIB-2026-005 · on drupal.org

This module lets people log into a website using their Microsoft account.

A visitor without an account could take over any user account on the website. They could log in as a site administrator without needing a password or access to an email address. This would let them see private information and change anything on the site.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Microsoft Entra ID SSO Login to 1.0.4.

For developers: what the fix changed

The fix is intended to validate API responses from Microsoft (specifically using ID token claims instead of unverified Graph API profile emails) to prevent account takeover, but the actual code changes for this validation (likely in SocialAuthEntraIdController.php) are missing from the provided diff.

The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.

Also in this release The release added account type support, updated the settings form with security options to block user 1 and admin roles, added a license to the font-awesome library, and updated documentation.

1.0.3 to 1.0.4 12 commits, 10 files.

  • .cspell.json +33 −0
  • README.md +270 −1
  • config/install/social_auth_entra_id.settings.yml +3 −0
  • config/schema/social_auth_entra_id.schema.yml +19 −0
  • social_auth_entra_id.info.yml +1 −1
  • social_auth_entra_id.libraries.yml +4 −0
  • social_auth_entra_id.routing.yml +6 −0
  • src/Controller/SocialAuthEntraIdController.php +0 −0
  • src/Form/SocialAuthEntraIdSettingsForm.php +164 −23
  • src/Plugin/Block/EntraIdLoginBlockBlock.php +84 −9

Full diff, 1.0.3 to 1.0.4

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Moderately critical: 4 updates

Include in your next routine update, within the month.

Role Delegation

Moderately critical · 58,074 sites report using it · SA-CONTRIB-2026-002 · on drupal.org

This module lets website managers give certain people the ability to assign specific roles to other users.

A user who is allowed to assign basic roles could give themselves the main administrator role. This would let them see all private data and change anything on the website. They could not do this if they only had a standard user account.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if the site uses the Views Bulk Operations module and the user can see a list of users.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Role Delegation to 8.x-1.5.

For developers: what the fix changed

The release diff is linked below. No summary of the fix has been written for this one.

8.x-1.4 to 8.x-1.5 7 commits, 14 files including 3 tests.

  • README.md +24 −41
  • role_delegation.api.php +23 −0
  • role_delegation.module +5 −11
  • role_delegation.services.yml +2 −1
  • src/Access/RoleDelegationAccessCheck.php +18 −12
  • src/DelegatableRoles.php +23 −1
  • src/DelegatableRolesInterface.php +1 −1
  • src/Form/RoleDelegationSettingsForm.php +1 −1
  • src/Plugin/Action/RoleDelegationAddRoleUser.php +1 −48
  • src/Plugin/Action/RoleDelegationManagerRoleUserTrait.php +77 −0
  • src/Plugin/Action/RoleDelegationRemoveRoleUser.php +1 −48

Full diff, 8.x-1.4 to 8.x-1.5

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Group invite

Moderately critical · 1,218 sites report using it · SA-CONTRIB-2026-001 · on drupal.org

This module lets group managers invite other people to join their group on the website.

A visitor without an account could view private content inside a group. They could read posts and information meant only for group members. They could not change or add any content to the group.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youThis applies if a user with the access right to create group invites takes certain uncommon actions.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Group invite to 2.3.9, 3.0.4 or 4.0.4, whichever branch you are on.

For developers: what the fix changed

The release diff is linked below. No summary of the fix has been written for this one.

2.3.8 to 2.3.9 1 commit, 4 files including 1 test.

  • config/optional/views.view.my_invitations.yml +225 −215
  • ginvite.module +8 −1
  • src/Controller/InvitationOperations.php +7 −0

Full diff, 2.3.8 to 2.3.9 · Full diff, 3.0.3 to 3.0.4 · Full diff, 4.0.3 to 4.0.4

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

AT Internet Piano Analytics

Moderately critical · 15 sites report using it · SA-CONTRIB-2026-004 · on drupal.org

This module connects a website to the AT Internet Piano Analytics service.

An administrator could put malicious code into text fields on the website. This code could then run when other people view the page. The attacker could use this to view hidden information or change content on the site.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youThis applies if a user has the access right to manage the analytics service.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate AT Internet Piano Analytics to 1.0.1 or 2.3.1, whichever branch you are on.

For developers: what the fix changed

The release diff is linked below. No summary of the fix has been written for this one.

1.0.0 to 1.0.1 1 commit, 1 file.

  • pianoanalytics.permissions.yml +1 −0

Full diff, 1.0.0 to 1.0.1 · Full diff, 2.3.0 to 2.3.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

AT Internet SmartTag

Moderately critical · no install count published · SA-CONTRIB-2026-003 · on drupal.org

This module links a website to the AT Internet SmartTag service.

A person with an administrator account could enter harmful scripts into text areas. These scripts would run when other visitors look at the affected pages. This would allow the attacker to read private details or alter website content.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youThis applies if a user has the access right to manage the smart tag service.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate AT Internet SmartTag to 1.0.1.

For developers: what the fix changed

The release diff is linked below. No summary of the fix has been written for this one.

1.0.0 to 1.0.1 1 commit, 1 file.

  • atsmarttag.permissions.yml +1 −0

Full diff, 1.0.0 to 1.0.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.