🚨 CVE-2026-81269
Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.
🎖@cveNotify
Drupal.org
Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108
This module enables you to store structured data in configurable fields and expose Data Field values through JSON endpoints. The module doesn't sufficiently check access when returning Data Field values through its JSON endpoint. This may allow anonymous…
September 2, 2026 40