Improper Authorization in Drupal's Entity API Affects Various Versions
CVE-2026-81158

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81158?

The Entity API in Drupal suffers from an incorrect authorization vulnerability that permits unauthorized access through forceful browsing. This flaw can lead to exposure of sensitive data by allowing users to access resources beyond their permitted boundaries. It is essential for users of Entity API versions ranging from 0.0.0 to 1.8.0 to apply necessary patches and updates to safeguard against potential exploitation.

Affected Version(s)

Entity API 0.0.0 < 1.8.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Douglas Groene (dgroene)
Matt Glaman (mglaman)
Sascha Grossenbacher (berdir)
Klaus Purer (klausi)
Kristiaan Van den Eynde (kristiaanvandeneynde)
Matt Glaman (mglaman)
Swan Kalata (akalata)
Greg Knaddison (greggles)
Lee Rowlands (larowlan)
Juraj Nemec (poker10)
Jess (xjm)
.