Skip to main content

Xray audit: This module enables you to audit a Drupal site by generating reports about its content, entities, display modes and configuration. (CVE-2026-96389)

0
Medium
Published: 10/07/2026 (10/07/2026, 16:30:05 UTC)
Source: GCVE Database
Product: drupal/xray_audit

Description

The Drupal Xray Audit module has a vulnerability where it insufficiently checks entity access when rendering entities via the display-mode example route. This can allow attackers to view unpublished or access-restricted content. However, field-level access controls remain enforced, preventing disclosure of sensitive fields such as user emails or password hashes. A patch is available to address this issue.

Affected software

Packagist:https://packages.drupal.org/8ghsa
drupal/xray_audit
Affected versions
<1.6.3>=2.0.0 <2.0.4>=3.0.0 <3.1.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 22:04:14 UTC

Technical Analysis

The Xray Audit module for Drupal generates reports about site content, entities, display modes, and configuration. It contains an access control vulnerability where entity access is not properly verified when rendering entities through the display-mode example route. This flaw permits attackers to view content that is unpublished or otherwise restricted. Despite this, field-level access restrictions still apply, so sensitive fields remain protected. The vulnerability affects versions prior to 1.6.3, versions from 2.0.0 up to but not including 2.0.4, and versions from 3.0.0 up to but not including 3.1.1. A patch is available to fix the issue.

Potential Impact

Attackers can view unpublished or access-restricted content on Drupal sites using the vulnerable Xray Audit module. Sensitive fields protected by field-level access controls are not exposed. This could lead to unauthorized disclosure of content that site administrators intended to keep private.

Mitigation Recommendations

A patch is available for this vulnerability. Site administrators should upgrade to versions 1.6.3 or later, 2.0.4 or later, or 3.1.1 or later of the Xray Audit module to remediate the issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
DRUPAL-CONTRIB-2026-206
Osv Schema Version
1.7.0
Aliases
["CVE-2026-96389"]
Ecosystems
["Packagist:https://packages.drupal.org/8"]

Threat ID: 6ac6bfe72cdf04f656828f51

Added to database: 10/07/2026, 21:55:51 UTC

Last enriched: 10/07/2026, 22:04:14 UTC

Last updated: 10/07/2026, 22:04:14 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses