Project:
Date:
2026-August-26
Vulnerability:
Access bypass
Affected versions:
<2.1.5
CVE IDs:
CVE-2026-81164
Description:
The Entity PDF module can create a PDF from any entity based on any View mode.
This module does not check entity view access when fetching a PDF route. This could result in a user accessing a PDF of an entity that they should not be able to view.
Solution:
Install the latest version:
- If you use the Entity PDF module for Drupal upgrade to Entity PDF 2.1.5.
Reported By:
Fixed By:
Coordinated By:
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team