CVE-2026-81158 PUBLISHED

Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113

Assigner: drupal
Reserved: 26.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.

Product Status

Vendor Drupal
Product Entity API
Versions
  • affected from 0.0.0 to 1.8.0 (excl.)

Credits

  • Douglas Groene (dgroene) finder
  • Matt Glaman (mglaman) finder
  • Sascha Grossenbacher (berdir) remediation developer
  • Klaus Purer (klausi) remediation developer
  • Kristiaan Van den Eynde (kristiaanvandeneynde) remediation developer
  • Matt Glaman (mglaman) remediation developer
  • Swan Kalata (akalata) coordinator
  • Greg Knaddison (greggles) coordinator
  • Lee Rowlands (larowlan) coordinator
  • Juraj Nemec (poker10) coordinator
  • Jess (xjm) coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE

Impacts

  • CAPEC-87 Forceful Browsing