CVE-2026-81166: Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-2026-109
Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Digital Signage Frameworkto a version that resolves this vulnerability.Fixed in 2.6.1Patch SA-CONTRIB-2026-109
Event History
Frequently Asked Questions
Which installations are affected?
Drupal sites using the Digital Signage Framework module in versions from 0.0.0 through 2.6.1 are affected.
What access does an attacker need to exploit this issue?
The available information identifies the issue as missing authorization enabling forceful browsing, but does not specify any required attacker privileges or authentication state.
How can I determine whether my site is exposed?
Check whether Digital Signage Framework is installed and whether its version is 2.6.1 or earlier. The provided information does not identify specific routes, features, or configuration conditions that would confirm exposure.