PT-2026-82369 · Drupal · Digital Signage Framework

·

CVE-2026-81166

·

Published

2026-08-26

·

Updated

2026-09-02

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Drupal Digital Signage Framework versions 0.0.0 through 2.6.1
Description A missing authorization issue allows forceful browsing. The module provides a route for signage devices to refresh dynamic blocks on a display, but it fails to verify if the requester is an authorized signage device or if the requested block is intended for display. Consequently, an anonymous visitor can read the rendered content of blocks they are not authorized to see. This is partially mitigated if block plugins perform their own access checks on the content.
Recommendations Update Drupal Digital Signage Framework to a version later than 2.6.1.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81166
DRUPAL-CONTRIB-2026-109

Affected Products

Digital Signage Framework