CVE-2026-81165 PUBLISHED

Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104

Assigner: drupal
Reserved: 26.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.

Product Status

Vendor Drupal
Product Blazy
Versions
  • affected from 0.0.0 to 3.0.18 (excl.)

Credits

  • Drew Webber (mcdruid) finder
  • Gaus Surahman (gausarts) remediation developer
  • Drew Webber (mcdruid) remediation developer
  • Swan Kalata (akalata) coordinator
  • Greg Knaddison (greggles) coordinator
  • Jess (xjm) coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE

Impacts

  • CAPEC-87 Forceful Browsing