VDB
Sign up
—

DRUPAL-CONTRIB-2026-064

Details

The Tealium iQ Tag Management module provides Drupal integration with Tealium iQ.

`tealiumiq` stores some data as PHP-serialized strings. In some situations, malicious data can be written directly to the field. This can lead to an Object Injection vulnerability when the data are unserialized.

This vulnerability is mitigated by the fact that an attacker must have permission to edit a content entity with an attached `tealiumiq` field. In addition, the core `jsonapi` module must be enabled with the option "Accept all JSON:API create, read, update, and delete operations", which is not the default, or the attacker needs some other way to edit field values directly.

**Note:** This project was marked as Unsupported by the Drupal Security Team on 2026-06-24 but a fix was released and the project restored on 2026-06-26.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/tealiumiq
Introduced in: 0Fixed in: 2.4.0

Upgrade drupal/tealiumiq to 2.4.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References