Drupal · Entity Pdf · CVE-2026-81164
**Name of the Vulnerable Software and Affected Versions**
Entity PDF versions 0.0.0 through 2.1.5
**Description**
Missing authorization in the Entity PDF module allows forceful browsing. The module fails to check entity view access when fetching a PDF route, which may allow a user to access a PDF of an entity they are not authorized to view.
**Recommendations**
Update Entity PDF to a version later than 2.1.5.