Drupal security updates, in plain English

Week of 2 September 2026

Drupal publishes security updates on Wednesdays. This week there were 14, all for modules. Between them they carry 16 security fixes, because a module can fix several bugs in one update: Email Verification / SMS Verification / OTP Verification fixed 2 and AI (Artificial Intelligence) fixed 2.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Critical: 4 updates

Cyber Essentials expects a fix within 14 days. Do it this week.

Unpublished Node Permissions

Critical · 4,321 sites report using it · SA-CONTRIB-2026-132 · on drupal.org

This module creates access rights per content type to control who can see unpublished pieces of content.

The module allows people to see published pieces of content even if other access rules should hide them. A visitor could read published content that should be hidden. They could not change any data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Unpublished Node Permissions to 8.x-1.8.

For developers: what the fix changed

The fix removes the code in unpublished_node_permissions_node_access_records within unpublished_node_permissions.module that incorrectly granted view access to published content. It also adds an update hook in unpublished_node_permissions.install to rebuild node access.

8.x-1.7 to 8.x-1.8 1 commit, 2 files.

  • unpublished_node_permissions.install +7 −0 fix
  • unpublished_node_permissions.module +0 −10 fix

Full diff, 8.x-1.7 to 8.x-1.8

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Jsonapi Role Access

Critical · 820 sites report using it · SA-CONTRIB-2026-127 · on drupal.org

This module restricts access to data feeds based on specific user roles.

The module does not properly enforce access rules when a request mimics a specific type of background web request. A visitor could read hidden data feeds or change data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Jsonapi Role Access to 2.0.2.

For developers: what the fix changed

The fix removes the `isXmlHttpRequest()` check from the early return condition in `checkUserRoleAccess` within `src/EventSubscriber/CheckUserRolePermissionEvent.php`, ensuring that requests mimicking XMLHttpRequests cannot bypass role access restrictions.

Also in this release Added a functional test to verify that XMLHttpRequest headers cannot bypass role restrictions.

2.0.1 to 2.0.2 1 commit, 2 files including 1 test.

  • src/EventSubscriber/CheckUserRolePermissionEvent.php +6 −5 fix

Full diff, 2.0.1 to 2.0.2

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Email Verification / SMS Verification / OTP Verification

Critical · 48 sites report using it · 2 security fixes

This module adds an extra layer of verification for user registration.

2 security fixes in one update. Email Verification / SMS Verification / OTP Verification fixed 2 separate security bugs this week: 1 cross site scripting, 1 access bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-125, is explained here and the full list is at the end of the card.

The module does not properly filter user supplied text before displaying it. A visitor could read hidden data or change data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Email Verification / SMS Verification / OTP Verification to 8.x-2.4.

For developers: what the fix changed

This release carries 2 security fixes. The summary below is for SA-CONTRIB-2026-125, the most serious of them.

The fix removes the insecure passing of error messages via the `q` URL parameter and its subsequent unescaped output in `otp_verification_form_user_register_form_alter` within `otp_verification.module`. It also updates message rendering in `src/Form/MiniorangeValidateUser.php` to use proper placeholders like `@msg` in the `t()` function and escapes the `tx_id` parameter to prevent XSS.

Also in this release The release also includes bug fixes related to session handling, cookie management, and redirect logic.

8.x-2.3 to 8.x-2.4 1 commit, 4 files.

  • otp_verification.module +66 −47 fix
  • src/Form/MiniorangeValidateUser.php +107 −56 fix
  • src/MiniorangeOtpUtilities.php +19 −4
  • src/Plugin/OtpValidation/OtpValidator.php +18 −2

Full diff, 8.x-2.3 to 8.x-2.4

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 2 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

Calculate Working Days

Critical · 26 sites report using it · SA-CONTRIB-2026-122 · on drupal.org

This module calculates working days between two dates.

The module does not properly restrict access to its settings page. A visitor could change the module settings. They could not read any hidden data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Calculate Working Days to 2.0.3.

For developers: what the fix changed

The fix updates the routing configuration in calculate_working_days.routing.yml to require the administer site configuration permission instead of access content.

2.0.2 to 2.0.3 1 commit, 1 file.

  • calculate_working_days.routing.yml +1 −1 fix

Full diff, 2.0.2 to 2.0.3

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Moderately critical: 10 updates

Include in your next routine update, within the month.

AI (Artificial Intelligence)

Moderately critical · 23,475 sites report using it · 2 security fixes

This module automatically translates pieces of content.

2 security fixes in one update. AI (Artificial Intelligence) fixed 2 separate security bugs this week: 1 access bypass, 1 cross site scripting. One update covers all of them. The most serious, SA-CONTRIB-2026-120, is explained here and the full list is at the end of the card.

The module does not properly check access rights on related fields or referenced items during translation. A user with an ordinary account could translate items they should not have access to. They could not read or update the affected items in other ways.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate AI (Artificial Intelligence) to 1.3.13 or 1.4.8, whichever branch you are on.

For developers: what the fix changed

This release carries 2 security fixes. The summary below is for SA-CONTRIB-2026-120, the most serious of them.

This fix adds a custom access callback named `checkAccess` in `AiTranslateController.php` to verify entity update and translation access. It also introduces field and referenced entity access checks in `TextExtractor.php` and `ReferenceFieldExtractor.php` to ensure users can only translate content they are permitted to view and update.

Also in this release The release also fixes a cross site scripting vulnerability in the AI Chatbot module by filtering YAML output and updates package versions.

1.3.12 to 1.3.13 5 commits, 10 files.

  • modules/ai_chatbot/src/Controller/DeepChatApi.php +1 −1
  • modules/ai_chatbot/src/Form/ChatForm.php +3 −3
  • modules/ai_ckeditor/package-lock.json +2 −2
  • modules/ai_ckeditor/package.json +1 −1
  • modules/ai_translate/ai_translate.routing.yml +2 −1 fix
  • modules/ai_translate/src/Controller/AiTranslateController.php +61 −1 fix
  • modules/ai_translate/src/Plugin/FieldTextExtractor/ReferenceFieldExtractor.php +2 −2 fix
  • modules/ai_translate/src/TextExtractor.php +4 −0 fix
  • ui/mdxeditor/package-lock.json +2 −2
  • ui/mdxeditor/package.json +1 −1

Full diff, 1.3.12 to 1.3.13 · Full diff, 1.4.7 to 1.4.8

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 2 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

PhotoSwipe - Responsive JavaScript Modal Image Gallery

Moderately critical · 18,493 sites report using it · SA-CONTRIB-2026-131 · on drupal.org

This module allows a website to add dynamic captions to image galleries.

The module does not properly clean user supplied text like image descriptions. A user with an ordinary account could read hidden data or change data on the website.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youAny site using this module where an attacker has an access right that permits them to enter HTML content.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate PhotoSwipe - Responsive JavaScript Modal Image Gallery to 5.0.9.

For developers: what the fix changed

The fix escapes the caption title using Drupal.checkPlain in modules/photoswipe_dynamic_caption/js/photoswipe_dynamic_caption.init.js and removes the previous escaping in modules/photoswipe_dynamic_caption/photoswipe_dynamic_caption.module.

Also in this release The release also improves media translation context handling in src/ImageDTO.php.

5.0.8 to 5.0.9 2 commits, 3 files.

  • modules/photoswipe_dynamic_caption/js/photoswipe_dynamic_caption.init.js +3 −1 fix
  • modules/photoswipe_dynamic_caption/photoswipe_dynamic_caption.module +4 −2 fix
  • src/ImageDTO.php +6 −2

Full diff, 5.0.8 to 5.0.9

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

AI Translate

Moderately critical · 5,948 sites report using it · SA-CONTRIB-2026-121 · on drupal.org

This module automatically translates pieces of content.

The module does not properly check access rights on related fields or referenced items during translation. A user with an ordinary account could translate items they should not have access to. They could not read or update the affected items in other ways.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate AI Translate to 1.3.2 or 1.4.1, whichever branch you are on.

For developers: what the fix changed

The fix replaces the generic permission check on the translation route with a custom access callback in `AiTranslateController::checkAccess` to ensure the user has update access to the entity and translation create access. It also adds field-level view access checks in `TextExtractor` and referenced entity view and update access checks in `ReferenceFieldExtractor`.

Also in this release The release also adds translation result caching, support for translating the 'description' field in custom menu link content, GitLab CI configuration, and documentation.

1.3.1 to 1.3.2 11 commits, 44 files including 8 tests.

  • .cspell-project-words.txt +11 −0
  • .gitlab-ci.yml +73 −0
  • .gitlab/issue_templates/bug_report.md +69 −0
  • .gitlab/issue_templates/feature_request.md +48 −0
  • .gitlab/issue_templates/plan.md +75 −0
  • .gitlab/issue_templates/support_request.md +64 −0
  • .gitlab/issue_templates/task.md +72 −0
  • .gitlab/merge_request_templates/Default.md +58 −0
  • README.md +4 −0
  • ai_translate.module +9 −37
  • ai_translate.post_update.php +24 −0
  • ai_translate.routing.yml +2 −1 fix

Full diff, 1.3.1 to 1.3.2 · Full diff, 1.4.0 to 1.4.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Mailer Plus Log

Moderately critical · 2,081 sites report using it · SA-CONTRIB-2026-128 · on drupal.org

This module records sent emails as pieces of content so they can be reviewed in a report.

The module does not hide sensitive information in the emails it records. An administrator could see one time login links for any account and use them to log in as that person. They could read hidden data and change data.

  • Who could do thisOnly someone with an administrator login.
  • Does it apply to youAny site using this module where an attacker has the access right to view the mail log.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Mailer Plus Log to 1.2.7.

For developers: what the fix changed

The fix introduces an email redactor service in `src/EmailRedactor.php` to remove sensitive login links from email bodies. This redaction is applied before saving the log entry in the `preSave` method of `src/Entity/SymfonyMailerLog.php`.

Also in this release Added tests, updated documentation, and added CSpell dictionary words.

1.2.6 to 1.2.7 1 commit, 17 files including 4 tests.

  • .gitlab-ci.yml +2 −0
  • README.md +31 −0
  • src/EmailRedactor.php +138 −0 fix
  • src/EmailRedactorInterface.php +36 −0 fix
  • src/Entity/SymfonyMailerLog.php +59 −0 fix
  • src/Entity/SymfonyMailerLogInterface.php +10 −0 fix
  • src/Plugin/Field/FieldFormatter/SymfonyMailerLogHtmlBody.php +13 −0 fix
  • src/RedactionMode.php +21 −0 fix
  • symfony_mailer_log.api.php +67 −0 fix
  • symfony_mailer_log.install +16 −0 fix
  • symfony_mailer_log.permissions.yml +3 −0 fix
  • symfony_mailer_log.post_update.php +77 −0 fix

Full diff, 1.2.6 to 1.2.7

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Media Library Importer

Moderately critical · 818 sites report using it · SA-CONTRIB-2026-129 · on drupal.org

This module imports media files into a media library.

The module copies files from any folder the web user can read into the public files folder. A user with an ordinary account could make private files available for anyone to download at a predictable web address. They could not change any data.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Media Library Importer to 2.1.6.

For developers: what the fix changed

The fix adds validation in `ConfigurationForm::validateForm` and `MediaLibraryImporterService::isWithinPublicFilesDirectory` to ensure that the configured import folder is located within the public files directory, preventing access to arbitrary directories.

Also in this release Added a 'process_queue_on_submit' setting, improved queue processing logic, updated documentation, and fixed PHPStan/PHPCS issues.

2.1.5 to 2.1.6 22 commits, 20 files.

  • .gitlab-ci.yml +30 −0
  • Agents.md +69 −0
  • CLAUDE.md +5 −0
  • README.md +58 −31
  • composer.json +1 −1
  • config/install/media_library_importer.settings.yml +1 −0
  • config/schema/media_library_importer.schema.yml +4 −0
  • doc/drupal_org_documentation/description.html +15 −1
  • media_image_exif_importer/media_image_exif_importer.info.yml +0 −1
  • media_image_exif_importer/src/Plugin/media/Source/ImageWithExif.php +1 −1
  • media_library_importer.install +13 −11
  • media_library_importer.links.menu.yml +12 −12

Full diff, 2.1.5 to 2.1.6

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Islandora

Moderately critical · 726 sites report using it · SA-CONTRIB-2026-126 · on drupal.org

This module provides background updates for advanced search and search result blocks.

The module does not properly check access rights when block IDs are sent to its public address. A visitor could read restricted block content. They could not change any data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module where a restricted block contains sensitive content and its ID is known or guessed.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Islandora to 2.19.0.

For developers: what the fix changed

The `islandora_advanced_search` sub-module has been completely removed from the codebase to resolve the access bypass vulnerability.

Also in this release The release also includes a fix for microservice rewrite for canonical event URLs.

2.18.5 to 2.19.0 2 commits, 55 files including 1 test.

  • modules/islandora_advanced_search/CONTRIBUTING.md +0 −73
  • modules/islandora_advanced_search/LICENSE +0 −339
  • modules/islandora_advanced_search/README.md +0 −261
  • modules/islandora_advanced_search/css/islandora_advanced_search.form.css +0 −37
  • modules/islandora_advanced_search/css/islandora_advanced_search.pager.css +0 −111
  • modules/islandora_advanced_search/docs/advanced_search_block_settings.png +0 −0
  • modules/islandora_advanced_search/docs/basic-input.png +0 −0
  • modules/islandora_advanced_search/docs/contextual_filter_settings.png +0 −0
  • modules/islandora_advanced_search/docs/demo.gif +0 −0
  • modules/islandora_advanced_search/docs/enable_index_hierarchy.png +0 −0
  • modules/islandora_advanced_search/docs/enable_index_hierarchy_processor.png +0 −0
  • modules/islandora_advanced_search/docs/exclude_facet_settings_exclude.png +0 −0

Full diff, 2.18.5 to 2.19.0

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Advanced Search

Moderately critical · 712 sites report using it · SA-CONTRIB-2026-118 · on drupal.org

This module provides background updates for advanced search and search result blocks.

The module does not properly check access rights when block IDs are sent to its public address. A visitor could read restricted block content. They could not change any data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module where a restricted block contains sensitive content and its ID is known or guessed.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Advanced Search to 2.4.5.

For developers: what the fix changed

The fix adds an access check for the view operation on the block entity in src/Controller/AjaxBlocksController.php before rendering it.

Also in this release Added a functional test to ensure block access is enforced.

2.4.2 to 2.4.5 1 commit, 2 files including 1 test.

  • src/Controller/AjaxBlocksController.php +1 −1 fix

Full diff, 2.4.2 to 2.4.5

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Webform Submissions Delete

Moderately critical · 393 sites report using it · SA-CONTRIB-2026-133 · on drupal.org

This module allows a website to delete form submissions in bulk using a specified date range.

The module does not properly restrict access to the delete page. A visitor could delete form submissions. They could not read any hidden data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Webform Submissions Delete to 8.x-1.2.

For developers: what the fix changed

The fix restricts access to the bulk delete form by changing the routing requirement in webform_submissions_delete.routing.yml from access content to webform.submission_purge_any and adds accessCheck(TRUE) to entity queries in src/Form/WebformResultsBulkDeleteForm.php.

Also in this release Added Drupal 11 compatibility and maintainer information.

8.x-1.1 to 8.x-1.2 3 commits, 5 files.

  • README.md +3 −0
  • composer.json +6 −1
  • src/Form/WebformResultsBulkDeleteForm.php +2 −2 fix
  • webform_submissions_delete.info.yml +1 −1
  • webform_submissions_delete.routing.yml +1 −1 fix

Full diff, 8.x-1.1 to 8.x-1.2

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Component blocks

Moderately critical · 179 sites report using it · SA-CONTRIB-2026-123 · on drupal.org

This module allows a website to use user interface patterns with blocks in the layout builder.

The module does not properly check user input before replacing text placeholders. A user with an ordinary account could read hidden data or change data.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youAny site using this module where an attacker has an access right to edit layouts.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Component blocks to 1.2.7.

For developers: what the fix changed

The fix applies Xss::filterAdmin to the value before token replacement in the ComponentBlock class.

1.2.6 to 1.2.7 1 commit, 2 files including 1 test.

  • src/Plugin/Block/ComponentBlock.php +2 −1 fix

Full diff, 1.2.6 to 1.2.7

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Monobank payment API

Moderately critical · 48 sites report using it · SA-CONTRIB-2026-130 · on drupal.org

This module connects a website to the Monobank payment service.

The module does not check the digital signature from Monobank before processing payment status updates. A visitor could change payment statuses. They could not read any hidden data.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youAny site using this module.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Monobank payment API to 1.0.3.

For developers: what the fix changed

Adds webhook signature verification in the `status` callback within `src/Controller/Pages.php` and implements the verification logic in `src/Monobank.php`.

Also in this release Added Drupal 12 support, dropped Drupal 9, migrated hooks to a new class using attributes, and updated translation method calls.

1.0.2 to 1.0.3 3 commits, 9 files.

  • monobank.info.yml +2 −2
  • monobank.module +12 −33
  • monobank.services.yml +4 −0
  • src/Controller/Pages.php +22 −15 fix
  • src/Form/MonobankPaymentsForm.php +9 −9
  • src/Form/SettingsForm.php +4 −4
  • src/Hook/MonobankHooks.php +84 −0
  • src/Monobank.php +115 −3 fix
  • src/Plugin/Basket/Payment/BasketMonobank.php +5 −5

Full diff, 1.0.2 to 1.0.3

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.