CVE-2026-81165: Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104
Published Sep 2, 2026
·Updated
Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.
Affected Software
2 affected components
Drupal Blazy>=0.0.0<=3.0.18
Blazy Project Blazy Drupal>=3.0.0<3.0.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/blazyto a version that resolves this vulnerability.Fixed in 3.0.18Patch SA-CONTRIB-2026-104
Event History
Sep 2, 2026
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
DescriptionWeakness
Data Sourced
via NVD·01:18 PM
DescriptionSeverityWeaknessAffected Software