DRUPAL-CONTRIB-2026-153

    Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2026-153

    DRUPAL-CONTRIB-2026-153

    Published: 9 Sept 2026Last Modified: 9 Sept 2026

    Summary:

    Details: The Ultimate Table Field module enables you to store table data in a field and edit each table cell through a dialog, using cell field plugins such as text, link, and file. The module doesn't sufficiently protect the route that opens the cell editor dialog. The route is accessible to anonymous users, who can open the dialog for any cell type. The dialog allows uploading files to the server location. This vulnerability is partially mitigated by the fact that only files with the `pdf`, `doc` and `docx` extensions are accepted.

    Affected packages

    Package

    Name: drupal/ultimate_table_field

    Purl: pkg:composer/drupal/ultimate_table_field?repository_url=https:%2F%2Fpackages.drupal.org%2F8

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.1.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DRUPAL-CONTRIB-2026-153 | CVE-DB