{"schema_version":"1.9.0","id":"DRUPAL-CONTRIB-2026-202","published":"2026-10-07T16:26:15Z","modified":"2026-10-07T20:15:06.887357405Z","aliases":["CVE-2026-107263"],"details":"This module provides a new UI experience for node editing using the Gutenberg Editor library.\n\nThe module does not sufficiently check entity access in several editor endpoints.\n\nThis vulnerability is mitigated by the fact that an attacker must have a role with the “use gutenberg” permission.","affected":[{"package":{"name":"drupal/gutenberg","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/gutenberg?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0"}],"database_specific":{"constraint":"<2.15.0"}},{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.7"}],"database_specific":{"constraint":">=3.0.0 <3.0.7"}}],"database_specific":{"affected_versions":"<2.15.0 || >=3.0.0 <3.0.7","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/gutenberg/DRUPAL-CONTRIB-2026-202.json"}}],"references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-202"}],"credits":[{"name":"Drew Webber (mcdruid)","contact":["https://www.drupal.org/u/mcdruid"]},{"name":"Tommaso Gregori (p1s1o)","contact":["https://www.drupal.org/u/p1s1o"]}]}