Missing Authorization Vulnerability in Drupal Digital Signage Framework
CVE-2026-81166

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81166?

A missing authorization vulnerability in the Drupal Digital Signage Framework can be exploited to perform forceful browsing. This allows unauthorized users to access sensitive data or functionalities that should be restricted. This issue impacts all versions from 0.0.0 to 2.6.1, highlighting the importance of proper security measures to protect against unauthorized access.

Affected Version(s)

Digital Signage Framework 0.0.0 < 2.6.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcus Johansson (marcus_johansson)
Daniel Speicher (danielspeicher)
Jürgen Haas (jurgenhaas)
Swan Kalata (akalata)
Greg Knaddison (greggles)
Jess (xjm)
.