{ "canonical_id": "drupal--65bf5646d9", "system_id": "drupal", "display_name": "Drupal", "category": "cms", "advisory_mode": "core", "title": "Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002", "summary": "
Bulk operations allow authorized users to modify several nodes at once from the Content page (/admin/content). A site builder can also add bulk operations to other pages using Views.
A bug in the core Actions system allows some users to modify some fields using bulk actions that they do not have permission to modify on individual nodes.
\nThis vulnerability is mitigated by the fact that an attacker must have permission to access /admin/content or other, custom views and to edit nodes.
In particular, the bulk operations
\nnow require the \"Administer content\" permission.
Install the latest version:
\nAll versions of Drupal 10 prior to 10.3 are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)