Intel

AIKIDO-2026-817324

drupal/entity is vulnerable to Information Disclosure

Information DisclosureCVE-2026-81158 Published 2 days ago

50

Medium Risk

This Affects:

PHPdrupal/entity
0.0.1 - 1.7.0
Fixed in 1.8.0
Are you affected? Scan for Free

TL;DR

An access control vulnerability in the Entity API module can expose unauthorized entity data through JSON:API collection endpoints. Exploitation requires both the Entity API and JSON:API modules to be enabled.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and Entity API and JSON:API modules are enabled.

Background info

drupal/entity is vulnerable to Information Disclosure in versions 0.0.1 - 1.7.0.

How to fix this

Upgrade the drupal/entity library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform