CVE-2026-81166

Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.
References
Link Resource
https://www.drupal.org/sa-contrib-2026-109 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:lakedrops:digital_signage_framework:*:*:*:*:*:drupal:*:*

History

16 Sep 2026, 19:45

Type Values Removed Values Added
First Time Lakedrops
Lakedrops digital Signage Framework
References () https://www.drupal.org/sa-contrib-2026-109 - () https://www.drupal.org/sa-contrib-2026-109 - Vendor Advisory
CPE cpe:2.3:a:lakedrops:digital_signage_framework:*:*:*:*:*:drupal:*:*

Information

Published : 2026-09-02 13:18

Updated : 2026-09-16 19:45


NVD link : CVE-2026-81166

Mitre link : CVE-2026-81166

CVE.ORG link : CVE-2026-81166


JSON object : View

Products Affected

lakedrops

  • digital_signage_framework
CWE
CWE-862

Missing Authorization