Drupal security updates, in plain English

Week of 12 August 2026

Drupal publishes security updates on Wednesdays. This week there were 5, all for modules.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Moderately critical: 5 updates

Include in your next routine update, within the month.

External Authentication

Moderately critical · 112,148 sites report using it · SA-CONTRIB-2026-098 · on drupal.org

This module allows people to log into the website using accounts from other systems.

A logged in user could trick the system into matching their account with another person because of how the database reads text. This would let them view and alter information belonging to that other person. They could not read or change unrelated website settings.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies to sites using specific text sorting settings in their MySQL or MariaDB database.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate External Authentication to 2.0.13.

For developers: what the fix changed

The fix updates the authmap schema in externalauth.install to make the authname and provider columns binary safe. It also adds a strict PHP comparison in Authmap::getUid within src/Authmap.php to ensure the fetched values exactly match the supplied values.

Also in this release The release also adds tests to verify the collation fix and updates a spellcheck configuration file.

2.0.12 to 2.0.13 1 commit, 5 files including 2 tests.

  • .gitlab-ci.yml +1 −1
  • externalauth.install +59 −0 fix
  • src/Authmap.php +6 −4 fix

Full diff, 2.0.12 to 2.0.13

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Diff

Moderately critical · 74,550 sites report using it · SA-CONTRIB-2026-096 · on drupal.org

This module lets people see the exact words that were added or removed between different saved versions of content.

A visitor could see the history of changes for certain pieces of data if they already had the access right to view the current version. They could read past versions of this data that should have been kept private. They could not make any changes to the content or its history.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Diff to 2.0.1 or 2.1.1, whichever branch you are on.

For developers: what the fix changed

The fix updates the entity access requirement in src/Routing/DiffRouteProvider.php to check for the 'view all revisions' permission instead of just the 'view' permission.

2.0.0 to 2.0.1 1 commit, 1 file.

  • src/Routing/DiffRouteProvider.php +1 −1 fix

Full diff, 2.0.0 to 2.0.1 · Full diff, 2.1.0 to 2.1.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Quick Tabs

Moderately critical · 24,791 sites report using it · SA-CONTRIB-2026-099 · on drupal.org

This module lets a website display different pieces of content inside clickable tabs.

A visitor could see hidden or unpublished pieces of content if an administrator had previously added them to a tab. They could view these specific items without the correct access rights. They could not change or delete any of this information.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Quick Tabs to 4.3.1.

For developers: what the fix changed

The fix updates `src/Plugin/TabType/BlockContent.php` and `src/Plugin/TabType/NodeContent.php` to strictly require an allowed access result (`isAllowed()`) rather than just checking for a forbidden result (`isForbidden()`) when rendering block plugins and node tabs. It also adds an explicit access check for reusable custom blocks in `BlockContent.php`.

Also in this release The release also replaces the js_cookie dependency with localStorage for tab memory, fixes an issue where inner tab titles were wiped during AJAX loads, and improves cacheability metadata handling.

4.3.0 to 4.3.1 3 commits, 31 files including 17 tests.

  • composer.json +1 −2
  • js/quicktabs.js +12 −15
  • quicktabs.info.yml +0 −1
  • quicktabs.install +5 −6
  • quicktabs.libraries.yml +0 −1
  • src/Controller/QuickTabsController.php +27 −5
  • src/Entity/QuickTabsInstance.php +1 −1
  • src/Form/QuickTabsInstanceEditForm.php +1 −1
  • src/Plugin/TabRenderer/QuickTabs.php +39 −26
  • src/Plugin/TabType/BlockContent.php +34 −8 fix
  • src/Plugin/TabType/NodeContent.php +17 −3 fix
  • src/Plugin/TabType/QtabsContent.php +17 −1

Full diff, 4.3.0 to 4.3.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Commerce PayPal

Moderately critical · 9,116 sites report using it · SA-CONTRIB-2026-095 · on drupal.org

This module allows a website to take payments through PayPal.

A visitor could trick the website into recording an order as paid when no money had actually been transferred. They could create false payment records in the system. They could not read any private information belonging to other customers.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youThis applies to sites using the Payflow Link payment method.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Commerce PayPal to 2.1.3 or 8.x-1.12, whichever branch you are on.

For developers: what the fix changed

The fix adds validation in the `onReturn` method of `PayflowLink.php` by verifying the `SECURETOKEN` against the order data and making a server-to-server API request to PayPal to confirm the transaction details and amount before creating the payment.

Also in this release Modernised logging to use `json_encode` instead of `print_r` and fixed PHPStan issues in `CreditMessaging.php`.

2.1.2 to 2.1.3 2 commits, 2 files.

  • src/Plugin/Commerce/PaymentGateway/PayflowLink.php +67 −29 fix
  • src/Plugin/views/area/CreditMessaging.php +8 −31

Full diff, 2.1.2 to 2.1.3 · Full diff, 8.x-1.11 to 8.x-1.12

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Entity Share Websub

Moderately critical · 498 sites report using it · SA-CONTRIB-2026-097 · on drupal.org

This module automatically copies content from one website to another.

A visitor could force the website server to make requests to other web addresses. This might allow them to see information from other servers that the website connects to. They could not change or delete any information on the website itself.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Entity Share Websub to 1.1.2.

For developers: what the fix changed

The fix introduces a `CallbackValidator` service to validate WebSub callback URLs against internal and reserved IP ranges, preventing SSRF attacks. This validation is applied in `Hub.php` before making requests and in `Subscription.php` during subscription creation, with exceptions configurable via a new `CallbackValidatorSettingsForm`.

Also in this release The release also updates core version requirements to include Drupal 11, modifies GitLab CI templates, adds subscription deletion events, and updates logger dependency injection.

1.1.1 to 1.1.2 17 commits, 39 files including 10 tests.

  • .cspell-project-words.txt +7 −0
  • .gitlab-ci.yml +16 −0
  • README.md +29 −0
  • entity_share_websub.info.yml +1 −1
  • modules/entity_share_websub_hub/config/install/entity_share_websub_hub.settings.yml +2 −0 fix
  • modules/entity_share_websub_hub/config/schema/entity_share_websub_hub.schema.yml +16 −0 fix
  • modules/entity_share_websub_hub/entity_share_websub_hub.info.yml +1 −1
  • modules/entity_share_websub_hub/entity_share_websub_hub.install +117 −0 fix
  • modules/entity_share_websub_hub/entity_share_websub_hub.links.menu.yml +5 −0 fix
  • modules/entity_share_websub_hub/entity_share_websub_hub.permissions.yml +5 −0 fix
  • modules/entity_share_websub_hub/entity_share_websub_hub.post_update.php +42 −0 fix
  • modules/entity_share_websub_hub/entity_share_websub_hub.routing.yml +11 −0 fix

Full diff, 1.1.1 to 1.1.2

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.