SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81165

MEDIUM · CVSS 5.3 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Blazy module for Drupal is vulnerable to incorrect authorization, enabling attackers to perform forceful browsing and potentially access restricted content. This issue affects all versions from 0.0.0 to 3.0.18, and organizations using these versions should prioritize remediation to protect sensitive data and maintain user access controls.

CVE
CVE-2026-81165
Severity
MEDIUM
CVSS
5.3
EPSS
0.31%

Original NVD Description

Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.