{"id":"CVE-2026-81164","summary":"Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114","details":"Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.","aliases":["DRUPAL-CONTRIB-2026-114"],"modified":"2026-09-04T03:47:25.832902148Z","published":"2026-09-02T12:31:48.297Z","database_specific":{"cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81164.json","cna_assigner":"drupal"},"references":[{"type":"WEB","url":"https://git.drupalcode.org/project/entity_pdf"},{"type":"WEB","url":"https://www.drupal.org/project/entity_pdf"},{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-114"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81164.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81164"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.drupalcode.org/project/entity_pdf","events":[{"introduced":"0"},{"fixed":"9679247b1d95816a7e9b815c702b721875ee5ec5"}],"database_specific":{"extracted_events":[{"introduced":"0.0.0"},{"fixed":"2.1.5"}],"source":"AFFECTED_FIELD"}}],"versions":["2.1.4","2.1.3","2.1.2","2.1.1","2.1.0","2.0.6","2.0.5","2.0.4","2.0.3","2.0.2","2.0.1","2.0.0","1.2.0","8.x-1.1","8.x-1.0","8.x-1.0-beta3","8.x-1.0-beta2","8.x-1.0-beta1","8.x-1.0-alpha9","8.x-1.0-alpha8","8.x-1.0-alpha7","8.x-1.0-alpha6","8.x-1.0-alpha5","8.x-1.0-alpha4","8.x-1.0-alpha3","8.x-1.0-alpha2","8.x-1.x-alpha1","8.x-1.0-alpha1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81164.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}