SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81164

MEDIUM · CVSS 5.4 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A missing authorization vulnerability in the Entity PDF module for Drupal allows attackers to exploit forceful browsing, potentially gaining unauthorized access to sensitive documents. This issue affects all versions from 0.0.0 to 2.1.5, and organizations using these versions should prioritize remediation to protect against unauthorized data exposure.

CVE
CVE-2026-81164
Severity
MEDIUM
CVSS
5.4
EPSS
0.23%

Original NVD Description

Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.