Missing Authorization Flaw in Drupal Entity PDF Affects Versions Up to 2.1.5
CVE-2026-81164

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81164?

A significant security issue has been identified in the Entity PDF module for Drupal, where a missing authorization allows unauthorized users to access potentially sensitive files. This vulnerability could lead to forceful browsing, granting unintended access to documents that should be restricted. The affected versions span from 0.0.0 to 2.1.5, highlighting the urgency for users to review their installations and apply relevant updates to mitigate any associated risks.

Affected Version(s)

Entity PDF 0.0.0 < 2.1.5

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcus Johansson (marcus_johansson)
Italo Mairo (itamair)
Wesley Sandra (weseze)
Swan Kalata (akalata)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
Jess (xjm)
.