Improper access control in Diff - CVE-2026-73478
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected module does not sufficiently restrict access to non-node entity revision diffs. A remote attacker can bypass implemented security restrictions and gain unauthorized access to sensitive information.