PT-2026-82362 · Drupal · Entity Api+1

·

CVE-2026-81158

·

Published

2026-08-26

·

Updated

2026-09-02

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Entity API versions 0.0.0 through 1.8.0
Description An incorrect authorization issue in the Entity API allows forceful browsing. The module fails to correctly apply access controls for JSON:API entity collection endpoints, leading to an information disclosure. This issue occurs when the JSON:API module is enabled alongside the Entity API module.
Recommendations Update Entity API to a version later than 1.8.0. As a temporary mitigation, disable the JSON:API module to prevent the exploitation of the entity collection endpoints.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81158
DRUPAL-CONTRIB-2026-113

Affected Products

Entity Api
Json Api