Information disclosure in Unpublished Node Permissions - CVE-2026-84920

 

Information disclosure in Unpublished Node Permissions - CVE-2026-84920

Published: September 3, 2026


Vulnerability identifier: #VU146855
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84920
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected module allows view access for published content, overriding other access mechanisms that might have been in place. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

Unpublished Node Permissions

How to mitigate CVE-2026-84920

Install updates from vendor's website.

Unpublished Node Permissions - update to 1.8.0

External References

Related Security Bulletins