—
DRUPAL-CONTRIB-2026-021
Details
This module moves files to and from private storage depending on the access of its owning entities.
The module does not always validate the access logic correctly, resulting in files attached to an entity not being protected in certain circumstances.
This vulnerability is mitigated by the fact that saving an entity a second time resolves the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/file_access_fix
Introduced in:
0Fixed in: 1.2.0Upgrade drupal/file_access_fix to 1.2.0 or newer (ecosystem packagist:https://packages.drupal.org/8).