Drupal · Digital Signage Framework · CVE-2026-81166
**Name of the Vulnerable Software and Affected Versions**
Drupal Digital Signage Framework versions 0.0.0 through 2.6.1
**Description**
A missing authorization issue allows forceful browsing. The module provides a route for signage devices to refresh dynamic blocks on a display, but it fails to verify if the requester is an authorized signage device or if the requested block is intended for display. Consequently, an anonymous visitor can read the rendered content of blocks they are not authorized to see. This is partially mitigated if block plugins perform their own access checks on the content.
**Recommendations**
Update Drupal Digital Signage Framework to a version later than 2.6.1.