CVE-2026-81165

Source
https://cve.org/CVERecord?id=CVE-2026-81165
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81165.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-81165
Aliases
Published
2026-09-02T12:32:14Z
Modified
2026-09-04T03:47:27Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104
Details

Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.

Database specific
{
    "cna_assigner": "drupal",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81165.json"
}
References

Affected packages

Git / git.drupalcode.org/project/blazy

Affected ranges

Type
GIT
Repo
https://git.drupalcode.org/project/blazy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
6671fb7c3193244382d0747df76bc55774fe08cd
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.0.0"
        },
        {
            "fixed": "3.0.18"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

3.*
3.0.0
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.x-dev
8.*
8.x-1.0-alpha1
8.x-1.0-alpha2
8.x-1.0-alpha3
8.x-1.0-alpha4
8.x-1.0-alpha5
8.x-1.0-beta1
8.x-1.0-beta2
8.x-1.0-beta3
8.x-1.0-beta4
8.x-1.0-beta5
8.x-1.0-beta6
8.x-1.0-rc1
8.x-1.0-rc2
8.x-1.0-rc3
8.x-1.0-rc4
8.x-2.0
8.x-2.0-alpha1
8.x-2.0-alpha2
8.x-2.0-alpha3
8.x-2.0-alpha4
8.x-2.0-alpha5
8.x-2.0-beta1
8.x-2.0-beta2
8.x-2.0-beta3
8.x-2.0-rc1
8.x-2.0-rc2
8.x-2.0-rc3
8.x-2.0-rc4
8.x-2.0-rc5
8.x-2.0-rc6
8.x-2.0-rc7
8.x-2.1
8.x-2.10
8.x-2.10-alpha1
8.x-2.10-beta1
8.x-2.10-rc1
8.x-2.10-rc2
8.x-2.10-rc3
8.x-2.11
8.x-2.12
8.x-2.13
8.x-2.14
8.x-2.15
8.x-2.16
8.x-2.17
8.x-2.17-beta1
8.x-2.17-rc1
8.x-2.17-rc2
8.x-2.17-rc3
8.x-2.17-rc4
8.x-2.17-rc5
8.x-2.2
8.x-2.3
8.x-2.4
8.x-2.5
8.x-2.6
8.x-2.7
8.x-2.8
8.x-2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81165.json"