CVE-2026-81166 Missing Authorization vulnerability in Drupal Digital… — CVE Notify — TG.ME

🚨 CVE-2026-81166
Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.

🎖@cveNotify
Drupal.org
Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-2026-109
The Digital Signage Framework module provides a route that signage devices can call to refresh dynamic blocks on a display. The route did not check whether the requester was a signage device, nor whether the requested block was one that the module delivers…
September 2, 2026 28