Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113
View online: https://www.drupal.org/sa-contrib-2026-113 Project: Entity API [1] Date: 2026-August-26 Security risk: *Moderately critical* 12 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:Default [2] Vulnerability: Information disclosure Affected versions: <1.8.0 CVE IDs: CVE-2026-81158 Description: The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties. The module doesn't correctly apply access controls for JSON:API entity collection endpoints. This exposes an information disclosure vulnerability. This vulnerability is mitigated by the fact that the JSON:API module must be enabled in combination with the Entity API module. Solution: Install the latest version: * If you use the Entity API module, upgrade to Entity API 8.x-1.8 [3]. Reported By: * Douglas Groene (dgroene) [4] * Matt Glaman (mglaman) [5] Fixed By: * Sascha Grossenbacher (berdir) [6] * Klaus Purer (klausi) [7] * Matt Glaman (mglaman) [8] Coordinated By: * Swan Kalata (akalata) [9] of the Drupal Security Team * Greg Knaddison (greggles) [10] of the Drupal Security Team * Lee Rowlands (larowlan) [11] of the Drupal Security Team * Juraj Nemec (poker10) [12] of the Drupal Security Team * Jess (xjm) [13] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [14] [1] https://www.drupal.org/project/entity [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/entity/releases/8.x-1.8 [4] https://www.drupal.org/u/dgroene [5] https://www.drupal.org/u/mglaman [6] https://www.drupal.org/u/berdir [7] https://www.drupal.org/u/klausi [8] https://www.drupal.org/u/mglaman [9] https://www.drupal.org/u/akalata [10] https://www.drupal.org/u/greggles [11] https://www.drupal.org/u/larowlan [12] https://www.drupal.org/u/poker10 [13] https://www.drupal.org/u/xjm [14] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org