—
DRUPAL-CONTRIB-2026-034
Details
Node view permissions module enables permissions "View own content" and "View any content" for each content type on permissions page The module doesn't sufficiently handle the case where a user is cancelled and their content is reassigned to the anonymous user. This vulnerability is mitigated by the fact that only private contents where anonymous should not have view access are affected, and only if a node was reassigned to the anonymous user.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/node_view_permissions
Introduced in:
0Fixed in: 1.7.0Upgrade drupal/node_view_permissions to 1.7.0 or newer (ecosystem packagist:https://packages.drupal.org/8).