Medium severity5.3NVD Advisory· Published Sep 2, 2026· Updated Oct 1, 2026
CVE-2026-81158
CVE-2026-81158
Description
Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 0.0.0 - 1.8.0
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2026-113nvdVendor Advisory
News mentions
2- Drupal: 25 Vulnerabilities Disclosed Together on September 2, 2026Vypr Intelligence · Sep 2, 2026
- Drupal: Eight Security Vulnerabilities Disclosed in Single AdvisoryVypr Intelligence · Aug 27, 2026