๐Ÿ” CVE Alert

CVE-2026-18259

HIGH 7.5

Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090

CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
4th

Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.

CWE CWE-208
Vendor drupal
Product token content access
Ecosystems
Industries
WebMedia
Published Aug 25, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for drupal token content access

Be the first to know when new high vulnerabilities affecting drupal token content access are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Drupal / Token Content Access
0.0.0 < 3.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
drupal.org: https://www.drupal.org/sa-contrib-2026-090

Credits

Robin (robincs) Kyrylo Loboda (lobodakyrylo) Bram Driesen (bramdriesen) cilefen (cilefen) Greg Knaddison (greggles) Juraj Nemec (poker10) Swan Kalata (akalata)