CVE-2026-16136

Authorization Bypass
Affects
Views Reference Filter
in
Drupal 7
No items found.
Versions
>=7.1.2 <=7.1.7

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Drupal is an open-source content management system known for its flexibility, robust features, and strong community support. Organizations of all sizes use it to build and manage dynamic websites and web applications.

Views Reference Filter (confusingly, with a machine name of entityreference_filter) adds Views-based filtering to entity reference fields, letting site builders limit selectable entities based on the results of another view. To support dependent exposed filters, the module registers an AJAX endpoint (entityreference_filter/update/%/%/%) that rebuilds a filter's option list on demand. In affected releases, this endpoint's menu access callback is hard-coded to TRUE, so Drupal performs no access check when dispatching the request — the module only verifies view access later, inside the callback body. As a result, a user who is not authorized to view a given view display can call the endpoint directly and obtain filter data derived from that restricted display, bypassing the view's access controls.

An authorization bypass vulnerability occurs when a system fails to properly enforce access controls, allowing an attacker to gain access to resources or perform actions that they are not supposed to have permission to access. This can happen due to flaws in the design or implementation of the authentication or authorization mechanisms.

Authorization bypass is a critical security risk because it can lead to severe consequences, including:

  • Unauthorized data access
  • Account takeovers, and
  • System compromise.

Details

Module Info

Vulnerability Info

This medium-severity vulnerability is found in versions of the Views Reference Filter module for Drupal 7 sites from 7.1.2 through 7.1.7 (inclusive).

Views Reference Filter exposes an AJAX callback used to refresh dependent exposed filters. The route entityreference_filter/update/%/%/% is registered in the module's hook_menu() implementation with 'access callback' => TRUE, which instructs Drupal to allow every request to the path without an access check at menu-dispatch time. The intended access verification was instead performed only inside the page callback body.

Because authorization was not declared at the framework level, the endpoint could be reached by any user — including anonymous users — and used to build a view display and return its filter/settings output regardless of whether the requester was authorized to access that display. An unauthenticated request to the endpoint for an otherwise access-restricted view returns that display's response instead of an "access denied" result, disclosing information from a view the user should not be able to see.

The fix registers a dedicated access callback, entityreference_filter_update_access(), in hook_menu() so that Drupal enforces the check at dispatch time — verifying the view and display exist and that $view->access($display) passes — before the callback runs.

Addressing the Issue

Users of this module should apply one of the following mitigations:

  • Until the update is applied, block or restrict the affected AJAX path (entityreference_filter/update/...) at the web server or reverse-proxy layer.
  • Review views that expose entity reference filters and confirm their access settings reflect who should be permitted to see the underlying data.
  • Sign up for post-EOL security support—HeroDevs customers get immediate access to a patched version of this module.

Credits

Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2026-16136
PROJECT Affected
Views Reference Filter
Versions Affected
>=7.1.2 <=7.1.7
NES Versions Affected
Published date
April 29, 2026
≈ Fix date
April 29, 2026
Category
Authorization Bypass
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Drupal 7
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.