Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108
Project: Data fieldDate: 2026-August-26Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Information disclosureAffected versions: <2.0.13CVE IDs: CVE-2026-81269Description: This module enables you to store structured data in configurable fields and expose Data Field values through JSON endpoints.
The module doesn't sufficiently check access when returning Data Field values through its JSON endpoint. This may allow anonymous users to access field values belonging to entities they cannot otherwise view, including unpublished content.Solution: Install the latest version:
- If you use the Data Field module, upgrade to Data Field 2.0.13
Reported By:
- Marcus Johansson (marcus_johansson)
- Drew Webber (mcdruid) of the Drupal Security Team
- Steven Jones (steven jones)
Fixed By:
- Joseph Olstad (joseph.olstad)
- NGUYEN Bao (lazzyvn)
- Marcus Johansson (marcus_johansson)
- Steven Jones (steven jones)
Coordinated By:
- Swan Kalata (akalata) of the Drupal Security Team
- David Stoline (dstol)
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team

