File Access Fix (deprecated)
2 security fixes in one update. File Access Fix (deprecated) fixed 2 separate security bugs this week: 2 access bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-021, is explained here and the full list is at the end of the card.
The system sometimes fails to apply the correct privacy rules when a piece of content is saved for the first time. Anyone visiting the site could view files that should be kept private. They could not change or delete the files.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate File Access Fix (deprecated) to 8.x-1.2.
For developers: what the fix changed
The fix updates src/FileAccessFixEntityHooks.php to pass the currently saved entity to anyFileUsageHasAnonAccess and use it for access checks, and adds a hookDownloadAllowed check to ensure file download access is properly validated before marking a file as public.
src/FileAccessFixEntityHooks.php+49 −5 fix
- Moderately critical · Access bypass · SA-CONTRIB-2026-021
- Moderately critical · Access bypass · SA-CONTRIB-2026-020