CVE-2026-16136
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Drupal is an open-source content management system known for its flexibility, robust features, and strong community support. Organizations of all sizes use it to build and manage dynamic websites and web applications.
Views Reference Filter (confusingly, with a machine name of entityreference_filter) adds Views-based filtering to entity reference fields, letting site builders limit selectable entities based on the results of another view. To support dependent exposed filters, the module registers an AJAX endpoint (entityreference_filter/update/%/%/%) that rebuilds a filter's option list on demand. In affected releases, this endpoint's menu access callback is hard-coded to TRUE, so Drupal performs no access check when dispatching the request — the module only verifies view access later, inside the callback body. As a result, a user who is not authorized to view a given view display can call the endpoint directly and obtain filter data derived from that restricted display, bypassing the view's access controls.
An authorization bypass vulnerability occurs when a system fails to properly enforce access controls, allowing an attacker to gain access to resources or perform actions that they are not supposed to have permission to access. This can happen due to flaws in the design or implementation of the authentication or authorization mechanisms.
Authorization bypass is a critical security risk because it can lead to severe consequences, including:
- Unauthorized data access
- Account takeovers, and
- System compromise.
Details
Module Info
- Product: Drupal 7
- Affected packages: Views Reference Filter
- Affected versions: >=7.1.2 <=7.1.7
- Repository: https://git.drupalcode.org/project/entityreference_filter
- Published packages: https://www.drupal.org/project/entityreference_filter
- Package manager: composer
- Fixed in: Views Reference Filter NES 7.1.8
Vulnerability Info
This medium-severity vulnerability is found in versions of the Views Reference Filter module for Drupal 7 sites from 7.1.2 through 7.1.7 (inclusive).
Views Reference Filter exposes an AJAX callback used to refresh dependent exposed filters. The route entityreference_filter/update/%/%/% is registered in the module's hook_menu() implementation with 'access callback' => TRUE, which instructs Drupal to allow every request to the path without an access check at menu-dispatch time. The intended access verification was instead performed only inside the page callback body.
Because authorization was not declared at the framework level, the endpoint could be reached by any user — including anonymous users — and used to build a view display and return its filter/settings output regardless of whether the requester was authorized to access that display. An unauthenticated request to the endpoint for an otherwise access-restricted view returns that display's response instead of an "access denied" result, disclosing information from a view the user should not be able to see.
The fix registers a dedicated access callback, entityreference_filter_update_access(), in hook_menu() so that Drupal enforces the check at dispatch time — verifying the view and display exist and that $view->access($display) passes — before the callback runs.
Addressing the Issue
Users of this module should apply one of the following mitigations:
- Until the update is applied, block or restrict the affected AJAX path (entityreference_filter/update/...) at the web server or reverse-proxy layer.
- Review views that expose entity reference filters and confirm their access settings reflect who should be permitted to see the underlying data.
- Sign up for post-EOL security support—HeroDevs customers get immediate access to a patched version of this module.
Credits
- ram4nd (ram4nd)