CVE-2026-81158: Entity API Project Entity API

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.

Affected products

  • Entity API Project Entity API: from 7.x-1.0, up to and including 7.x-1.11; from 8.x-0.1, before 8.x-1.8 (fixed in 8.x-1.8)

Published 2026-09-02. Last modified 2026-10-01.