{"id":"DRUPAL-CONTRIB-2026-132","details":"This module creates permissions per node content type to control access to unpublished content.\n\nThe module has allowed view access for published content, overriding other access mechanisms that might have been in place.","aliases":["CVE-2026-84920"],"modified":"2026-09-02T19:55:49.823522Z","published":"2026-09-02T16:38:32Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-132"}],"affected":[{"package":{"name":"drupal/unpublished_node_permissions","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/unpublished_node_permissions?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0"}],"database_specific":{"constraint":"\u003c1.8.0"}}],"database_specific":{"affected_versions":"\u003c1.8.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/unpublished_node_permissions/DRUPAL-CONTRIB-2026-132.json"}}],"schema_version":"1.9.0","credits":[{"name":"Erwin Eggenberger (eeg)","contact":["https://www.drupal.org/u/eeg"]},{"name":"Jon Jordan (joncjordan)","contact":["https://www.drupal.org/u/joncjordan"]}]}