Project: 
Date: 
2026-August-26
Vulnerability: 
Information disclosure
Affected versions: 
<1.8.0
CVE IDs: 
CVE-2026-81158
Description: 

The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties.

The module doesn't correctly apply access controls for JSON:API entity collection endpoints. This exposes an information disclosure vulnerability.

This vulnerability is mitigated by the fact that the JSON:API module must be enabled in combination with the Entity API module.

Solution: 

Install the latest version:

Coordinated By: