{"id":"DRUPAL-CONTRIB-2026-208","details":"The DKAN module enables organizations and individuals to build open data portals in Drupal. The DKAN datastore imports tabular data files into database tables and exposes them for querying with a JSON API.\n\nThe module does not correctly check access for all of its endpoints, leading to a potential access bypass.\n\nThe vulnerability is mitigated by the fact that it is only impactful for sites that do not give \"access content\" permission to the anonymous role.","aliases":["CVE-2026-107267"],"modified":"2026-10-07T20:15:05.846795734Z","published":"2026-10-07T16:33:07Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-208"}],"affected":[{"package":{"name":"drupal/dkan","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/dkan?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.4"}],"database_specific":{"constraint":"\u003c4.0.4"}},{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.1.5"}],"database_specific":{"constraint":"\u003e=4.1.0 \u003c4.1.5"}}],"database_specific":{"affected_versions":"\u003c4.0.4 || \u003e=4.1.0 \u003c4.1.5","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/dkan/DRUPAL-CONTRIB-2026-208.json"}}],"schema_version":"1.9.0","credits":[{"name":"Rodel Duterte (rduterte)","contact":["https://www.drupal.org/u/rduterte"]}]}