Drupal security updates, in plain English

Week of 28 January 2026

Drupal publishes security updates on Wednesdays. This week there were 2, all for modules.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Moderately critical: 1 update

Include in your next routine update, within the month.

Drupal Canvas

Moderately critical · 11,747 sites report using it · SA-CONTRIB-2026-006 · on drupal.org

It provides a visual tool to build and design website pages directly in the browser.

The module does not correctly check access rights for pages that are not published. Anyone visiting the site could see the content of these hidden pages. They could not change any information.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youA site is affected if a page built with this tool has been published and then unpublished.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Drupal Canvas to 1.0.4.

For developers: what the fix changed

Updates `checkAccess` in `src/Entity/PageAccessControlHandler.php` to ensure that users with only the 'access content' permission can only view published pages.

Also in this release Version bumps in package files and updated tests.

1.0.3 to 1.0.4 2 commits, 4 files including 1 test.

  • src/Entity/PageAccessControlHandler.php +12 −3 fix
  • ui/package-lock.json +2 −2
  • ui/package.json +1 −1

Full diff, 1.0.3 to 1.0.4

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Less critical: 1 update

Fix with the next routine update.

Central Authentication System (CAS) Server

Less critical · 303 sites report using it · SA-CONTRIB-2026-007 · on drupal.org

It allows other websites to use your website database to check user login details.

The module does not properly clean up text provided by users before sending it to other systems. A person with an ordinary account could insert hidden code into their profile fields. They could not read or change any private data on the website.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youA site is affected if a user can type code into a profile field and the site is set up to send that field to other systems.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this less critical. Fix it with the next routine update.

Tell your developerUpdate Central Authentication System (CAS) Server to 2.0.3 or 2.1.2, whichever branch you are on.

For developers: what the fix changed

The fix replaces manual string concatenation with `DOMDocument` to build XML responses in `ProxyController` and `TicketValidationController`, ensuring that user-supplied attribute values are properly escaped and preventing XML element injection.

Also in this release The release also deprecates the use of the term 'whitelist' in favour of `loadServiceFromUri`, enforces coding standards with a new `phpcs.xml`, and updates tests accordingly.

2.0.2 to 2.0.3 7 commits, 9 files including 2 tests.

  • .cspell-project-words.txt +2 −0
  • phpcs.xml +12 −0
  • src/Configuration/ConfigHelper.php +9 −3
  • src/Controller/ProxyController.php +65 −26 fix
  • src/Controller/TicketValidationController.php +231 −121 fix
  • src/Controller/UserActionController.php +4 −4
  • src/Controller/XmlResponseBase.php +27 −0 fix

Full diff, 2.0.2 to 2.0.3 · Full diff, 2.1.1 to 2.1.2

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.