PT-2026-82362 · Drupal · Entity Api+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Entity API versions 0.0.0 through 1.8.0
Description
An incorrect authorization issue in the Entity API allows forceful browsing. The module fails to correctly apply access controls for JSON:API entity collection endpoints, leading to an information disclosure. This issue occurs when the JSON:API module is enabled alongside the Entity API module.
Recommendations
Update Entity API to a version later than 1.8.0.
As a temporary mitigation, disable the JSON:API module to prevent the exploitation of the entity collection endpoints.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Entity Api
Json Api