PatchSiren cyber security CVE debrief
CVE-2026-107267 drupal CVE debrief
The DKAN module for Drupal has a vulnerability that could lead to an access bypass due to incorrect access checks on some endpoints. This issue primarily affects sites that have not granted 'access content' permission to the anonymous role. The vulnerability is confirmed in DKAN module versions less than 4.0.4 and 4.1.0 to 4.1.4. Official sources indicate that sites with 'access content' permission granted to the anonymous role are not impacted. Defenders should prioritize verifying their DKAN module version and ensuring proper access controls are in place.
- Vendor
- drupal
- Product
- dkan
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Drupal site administrators and security teams should assess exposure and verify DKAN module versions. They should review access controls and update or adjust configurations as necessary to prevent potential access bypass. This includes verifying DKAN module version, reviewing access controls, and updating or adjusting configurations as necessary.
Why it matters
Defenders should care about this vulnerability as it could lead to unauthorized access and data exposure in Drupal sites using the DKAN module. Site administrators and security teams should verify their DKAN module version, review access controls, and update or adjust configurations as necessary to prevent potential access bypass.
- Potential unauthorized access to data via DKAN datastore endpoints.
- Need to verify and adjust access controls for the DKAN module.
- Possible impact on data integrity if access controls are not properly configured.
Technical summary
The DKAN module for Drupal does not correctly check access for all of its endpoints, potentially leading to an access bypass. This issue is mitigated as it only impacts sites that do not give 'access content' permission to the anonymous role. The vulnerability is confirmed in DKAN module versions less than 4.0.4 and 4.1.0 to 4.1.4. Official sources indicate that sites with 'access content' permission granted to the anonymous role are not impacted. Defenders should prioritize verifying their DKAN module version and ensuring proper access controls are in place.
Defensive priority
Defenders should prioritize verifying their DKAN module version and ensuring proper access controls are in place.
Recommended defensive actions
- Verify DKAN module version and update to 4.0.4 or later if using a vulnerable version.
- Ensure 'access content' permission is not granted to the anonymous role if not required.
- Review and adjust access controls for DKAN datastore endpoints.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The vulnerability is confirmed in DKAN module versions less than 4.0.4 and 4.1.0 to 4.1.4. Official sources indicate that sites with 'access content' permission granted to the anonymous role are not impacted.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107267 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107267
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107267 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107267
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
DRUPAL-CONTRIB-2026-208
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Packagist/DRUPAL-CONTRIB-2026-208.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://www.drupal.org/sa-contrib-2026-208
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.