Improper access control in Entity Reference Manager (Merge entities) - CVE-2026-107251

 

Improper access control in Entity Reference Manager (Merge entities) - CVE-2026-107251

Published: October 9, 2026


Vulnerability identifier: #VU154021
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-107251
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the affected module does not sufficiently restrict access to all entity management operations. A remote attacker can view content to access the entity merge functionality and delete arbitrary nodes, taxonomy terms or media entities.


Affected software

Entity Reference Manager (Merge entities)

How to mitigate CVE-2026-107251

Install updates from vendor's website.

Entity Reference Manager (Merge entities) - update to 1.0.3

External References

Related Security Bulletins