Description
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing. This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.
Problem types
CWE-754 Improper Check for Unusual or Exceptional Conditions
Product status
0.0.0 (semver) before 1.7.0
2.0.0 (semver) before 2.0.1
Credits
Adam Shepherd (adamps)
Bálint Nagy (nagy.balint)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2026-034