Cloud
2 security fixes in one update. Cloud fixed 2 separate security bugs this week: 2 remote code execution. One update covers all of them. The most serious, SA-CONTRIB-2026-177, is explained here and the full list is at the end of the card.
An administrator account could run dangerous operating system commands on the web server by entering malicious web addresses. They could read any file on the server and change the core website code. They could not do this without the access right to add or edit server templates.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies if the Kubernetes feature is turned on and the attacker has the access right to launch server templates.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Cloud to 7.0.1.
For developers: what the fix changed
It is unclear where the exact sanitisation occurs in the module's code, but the fix appears to rely on updating the `cloud_orchestrator` Docker image version to 7.0.1 in the Kubernetes deployment configuration files.
The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.
Also in this release The release also adds new AWS region locations, updates type hints for PHP 8.4 compatibility, and removes 'default_argument_skip_url' from various view configurations.
.gitlab-ci.yml+6 −4README.md+3 −3cloud.doxyfile+1 −1cloud.info.yml+1 −1cloud.install+31 −4cloud.module+5 −5config/install/field.storage.cloud_config.field_self_signed_cert_path.yml+1 −4config/install/views.view.cloud_launch_template.yml+0 −1deployments/cfn/nested/cloud_orchestrator_full.yaml+2 −1deployments/cfn/nested/cloud_orchestrator_full_manual_vpc.yaml+2 −1deployments/cfn/nested/cloud_orchestrator_single.yaml+2 −1deployments/cfn/nested/cloud_orchestrator_single_ami.yaml+2 −1
- Critical · Remote code execution · SA-CONTRIB-2026-177
- Critical · Remote code execution · SA-CONTRIB-2026-176