SB2026092437 - Improper access control in Smart Content module for Drupal
Published: September 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-96386)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the Smart Content Block submodule does not sufficiently check block access when it renders the blocks of a "Display Blocks" reaction through the module's AJAX endpoint. A remote attacker can gain access to sensitive information on the system.
Remediation
Install update from vendor's website.