{"id":"DRUPAL-CONTRIB-2026-182","details":"This module enables you to add an extra authentication layer to the API.\n\nThe module does not sufficiently validate authentication requirements for all API requests, which can result in an access bypass vulnerability.","aliases":["CVE-2026-96385"],"modified":"2026-09-23T19:15:06.681833074Z","published":"2026-09-23T17:10:00Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-182"}],"affected":[{"package":{"name":"drupal/rest_api_authentication","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/rest_api_authentication?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.0"}],"database_specific":{"constraint":"\u003c3.2.0"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/rest_api_authentication/DRUPAL-CONTRIB-2026-182.json","affected_versions":"\u003c3.2.0"}}],"schema_version":"1.9.0","credits":[{"name":"Drew Webber (mcdruid)","contact":["https://www.drupal.org/u/mcdruid"]}]}