Improper access control in Entity Reference Manager (Merge entities) - CVE-2026-107251
Published: October 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected module does not sufficiently restrict access to all entity management operations. A remote attacker can view content to access the entity merge functionality and delete arbitrary nodes, taxonomy terms or media entities.