{"id":"DRUPAL-CONTRIB-2026-138","details":"This module enables you to add key-based authentication on a per-user  \nbasis.\n\nThe module doesn't cache per user, potentially allowing an attacker to view another user's authentication keys, if the attacker has the same permissions.\n\nThis vulnerability is mitigated by the fact that the site must have the `dynamic_page_cache` module enabled.","aliases":["CVE-2026-87940"],"modified":"2026-09-09T19:25:58.110775Z","published":"2026-09-09T17:17:50Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-138"}],"affected":[{"package":{"name":"drupal/key_auth","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/key_auth?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.4"}],"database_specific":{"constraint":"\u003c2.2.4"}}],"database_specific":{"affected_versions":"\u003c2.2.4","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/key_auth/DRUPAL-CONTRIB-2026-138.json"}}],"schema_version":"1.9.0","credits":[{"name":"Utkarsh Choudhary (sisyphus_ut)","contact":["https://www.drupal.org/u/sisyphus_ut"]}]}