Impact
The flaw in Drupal Blazy an incorrect Authorization vulnerability that enables forceful browsing. An attacker can craft requests to resources that should be restricted, thereby gaining unauthorized access to content or functionality that is otherwise protected by the system's permissions logic. The weakness is modeled by CWE-863 and results in a direct breach of access control.
Affected Systems
Drupal Blazy users running any version from 0.0.0 up to and including 3.0.18 are affected. The issue does not apply to versions released after 3.0.18.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests it may not be widely exploited yet. However, the Attack vector is inferred to be remote via HTTP requests targeting protected routes, and the exploit requires only knowledge of the resource identifier and the ability to send a request. Because the vulnerability allows bypassing Authorization checks, the potential impact includes unauthorized data exposure and possible escalation to higher privilege activities. The lack of a published CVSS score limits precise severity assessment, but the nature of the flaw indicates a non‑negligible risk to confidentiality and integrity.
OpenCVE Enrichment