CVE-2026-81158 Incorrect Authorization vulnerability in Drupal Entity… — CVE Notify — TG.ME

🚨 CVE-2026-81158
Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.

🎖@cveNotify
Drupal.org
Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113
The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties. The module doesn't correctly apply access controls for JSON:API entity collection endpoints. This exposes an information disclosure…
September 2, 2026 6