CVE-2026-81158: Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113
Published Sep 2, 2026
·Updated
Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.
Affected Software
1 affected component
Drupal Entity API>=0.0.0<=1.8.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/entity_apito a version that resolves this vulnerability.Fixed in 1.8.0 - Compensating control
Mitigate forceful browsing by restricting access to Drupal Entity API / endpoints (e.g., via web server rules/WAF and/or authenticated access controls) until upgraded to a fixed version.
Event History
Sep 2, 2026
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionWeakness
Data Sourced
via NVD·01:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Drupal installations using the Entity API module are affected if the module version is from 0.0.0 through 1.8.0.
2
What type of access could an attacker gain?
The vulnerability is an incorrect-authorization issue that allows forceful browsing, which can result in information disclosure.