CVE-2026-81166: Lakedrops Digital Signage Framework
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.
Affected products
- Lakedrops Digital Signage Framework: before 2.6.1 (fixed in 2.6.1)
Published 2026-09-02. Last modified 2026-09-16.