Drupal · Blazy · CVE-2026-81165
**Name of the Vulnerable Software and Affected Versions**
Drupal Blazy versions 0.0.0 through 3.0.18
**Description**
An incorrect authorization issue allows forceful browsing. The module enables users to display a field of a target entity using a Blazy Filter plugin shortcode. Because the module does not consistently check entity view access, a user with access to a Blazy-enabled text format can render a field from an entity they are not permitted to view. This is limited to fields that the shortcode is capable of rendering.
**Recommendations**
Update Drupal Blazy to a version later than 3.0.18.