Incorrect Authorization Vulnerability in Blazy by Drupal
CVE-2026-81165

Currently unrated

Key Information:

Vendor

Drupal

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-81165?

A vulnerability in the Blazy module for Drupal permits unauthorized users to access restricted areas of the application, leading to potential unauthorized actions within the system. This issue affects all versions from 0.0.0 to 3.0.18, and it is crucial for users to address this flaw to prevent unauthorized access and maintain system integrity.

Affected Version(s)

Blazy 0.0.0 < 3.0.18

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Drew Webber (mcdruid)
Gaus Surahman (gausarts)
Drew Webber (mcdruid)
Swan Kalata (akalata)
Greg Knaddison (greggles)
Jess (xjm)
.