PatchSiren cyber security CVE debrief
CVE-2026-107309 Drupal CVE debrief
The Drupal Easy Breadcrumb module is vulnerable to insufficient access checks on parent terms in taxonomy hierarchies. This allows unauthorized users to access unpublished terms if the 'Add parent hierarchy' setting is enabled and at least one term in the hierarchy is unpublished. The vulnerability requires verification of the module version and configuration to prevent potential data exposure or elevation of privileges. Defenders should prioritize verifying their Drupal installations for the Easy Breadcrumb module version less than 2.0.11 and consider restricting access to taxonomy term hierarchies until the module is updated.
- Vendor
- Drupal
- Product
- Easy Breadcrumb
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Drupal site administrators and security teams should assess exposure and prioritize updating the Easy Breadcrumb module to prevent unauthorized access to taxonomy term hierarchies.
Why it matters
Defenders should care about this vulnerability because it allows unauthorized users to access unpublished terms in taxonomy hierarchies if the 'Add parent hierarchy' setting is enabled. This requires verification of the module version and configuration to prevent potential data exposure or elevation of privileges.
- Potential unauthorized access to unpublished taxonomy terms
- Possible elevation of privileges for users with limited access
- Need for verification of module version and configuration
- Potential for data exposure or manipulation
Technical summary
The Drupal Easy Breadcrumb module does not sufficiently check for view access of parent terms before rendering the crumb segment. This vulnerability requires the 'Add parent hierarchy' setting to be enabled and at least one term in the hierarchy to be unpublished. The vulnerability allows unauthorized users to access unpublished terms in taxonomy hierarchies if the 'Add parent hierarchy' setting is enabled. This requires verification of the module version and configuration to prevent potential data exposure or elevation of privileges.
Defensive priority
Defenders should prioritize verifying their Drupal installations for the Easy Breadcrumb module version less than 2.0.11 and consider restricting access to taxonomy term hierarchies until the module is updated.
Recommended defensive actions
- Verify the version of the Easy Breadcrumb module in your Drupal installation and update to version 2.0.11 or later if necessary.
- Restrict access to taxonomy term hierarchies until the module is updated.
- Monitor for any suspicious activity related to taxonomy term access.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability is confirmed by the Drupal security team and is tracked as DRUPAL-CONTRIB-2026-212. The affected module is drupal/easy_breadcrumb with version less than 2.0.11. The setting 'Add parent hierarchy' (term_hierarchy) must be enabled, and at least one term has a term in the parent hierarchy that is unpublished. This information is based on the official CVE Program record and the NIST NVD detail page.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107309 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107309
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107309 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107309
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
DRUPAL-CONTRIB-2026-212
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Packagist/DRUPAL-CONTRIB-2026-212.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://www.drupal.org/sa-contrib-2026-212
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.