Date: 
Tuesday, Aug 25th, 2026
Advisory ID: 
BACKDROP-SA-CONTRIB-2026-019
Security risk: 
Moderately Critical
Vulnerability: 
Access bypass
Versions affected: 

All Token Content Access versions prior to 1.x-1.2.2

Description: 

The Token Content Access module enables site administrators to provide access to content using access tokens.

The module does not sufficiently protect access token comparison in some cases. This could allow a persistent attacker to use a timing attack to guess a valid access token and bypass access restrictions for content protected by this module.

This vulnerability is mitigated by the fact that an attacker must know or discover both the URL and the parameter key for content protected by Token Content Access, and exploiting the issue requires measuring timing differences in token comparison responses.

Solution: 

Upgrade your site to the most recent version of Token Content Access Download available on the Token Content Access release page. See the update instructions, if needed.

Reported By: 
Coordinated By: 

Security email list

Backdrop maintains a security mailing list. Whenever a security release comes out, an email will be sent to everyone subscribed to that list, announcing the new release. Please follow the steps below to join the Security email list.

  1. Log in to backdropcms.org
  2. Edit your profile
  3. Switch to the "Subscriptions" tab
  4. Check the box labeled "Security updates"
  5. Save the form