View online: https://www.drupal.org/sa-contrib-2026-114 Project: Entity PDF [1] Date: 2026-August-26 Security risk: *Moderately critical* 13 ∕ 25 AC:None/A:User/CI:Some/II:None/E:Theoretical/TD:All [2] Vulnerability: Access bypass Affected versions: <2.1.5 CVE IDs: CVE-2026-81164 Description: The Entity PDF module can create a PDF from any entity based on any View mode. This module does not check entity view access when fetching a PDF route. This could result in a user accessing a PDF of an entity that they should not be able to view. Solution: Install the latest version: * If you use the Entity PDF module for Drupal upgrade to Entity PDF 2.1.5 [3]. Reported By: * Marcus Johansson (marcus_johansson) [4] Fixed By: * Italo Mairo (itamair) [5] * Wesley Sandra (weseze) [6] Coordinated By: * Swan Kalata (akalata) [7] of the Drupal Security Team * Greg Knaddison (greggles) [8] of the Drupal Security Team * Juraj Nemec (poker10) [9] of the Drupal Security Team * Jess (xjm) [10] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [11] [1] https://www.drupal.org/project/entity_pdf [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/entity_pdf/releases/2.1.5 [4] https://www.drupal.org/u/marcus_johansson [5] https://www.drupal.org/u/itamair [6] https://www.drupal.org/u/weseze [7] https://www.drupal.org/u/akalata [8] https://www.drupal.org/u/greggles [9] https://www.drupal.org/u/poker10 [10] https://www.drupal.org/u/xjm [11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....