{"id":"DRUPAL-CONTRIB-2026-185","details":"This module runs a client-side accessibility checker that automatically reports results to dashboard views over an API.\n\nThe module incorrectly described a permission as a \"view\" permission when it grants edit and delete access to module data, resulting in a potential access bypass.","aliases":["CVE-2026-96390"],"modified":"2026-09-23T19:15:05.310550211Z","published":"2026-09-23T17:18:31Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-185"}],"affected":[{"package":{"name":"drupal/editoria11y","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/editoria11y?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.23"}],"database_specific":{"constraint":"\u003c2.2.23"}},{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.9"}],"database_specific":{"constraint":"\u003e=3.0.0 \u003c3.0.9"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/editoria11y/DRUPAL-CONTRIB-2026-185.json","affected_versions":"\u003c2.2.23 || \u003e=3.0.0 \u003c3.0.9"}}],"schema_version":"1.9.0","credits":[{"name":"Maksim Hayder (tr_jan)","contact":["https://www.drupal.org/u/tr_jan"]}]}