—
DRUPAL-CONTRIB-2026-185
Details
This module runs a client-side accessibility checker that automatically reports results to dashboard views over an API.
The module incorrectly described a permission as a "view" permission when it grants edit and delete access to module data, resulting in a potential access bypass.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/editoria11y
Introduced in:
0Fixed in: 2.2.23Upgrade drupal/editoria11y to 2.2.23 or newer (ecosystem packagist:https://packages.drupal.org/8).