Description
Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Access Bypass
Action: Patch Update
AI Analysis

Impact

The flaw in Drupal Blazy an incorrect Authorization vulnerability that enables forceful browsing. An attacker can craft requests to resources that should be restricted, thereby gaining unauthorized access to content or functionality that is otherwise protected by the system's permissions logic. The weakness is modeled by CWE-863 and results in a direct breach of access control.

Affected Systems

Drupal Blazy users running any version from 0.0.0 up to and including 3.0.18 are affected. The issue does not apply to versions released after 3.0.18.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests it may not be widely exploited yet. However, the Attack vector is inferred to be remote via HTTP requests targeting protected routes, and the exploit requires only knowledge of the resource identifier and the ability to send a request. Because the vulnerability allows bypassing Authorization checks, the potential impact includes unauthorized data exposure and possible escalation to higher privilege activities. The CVSS score of 5.3 indicates moderate severity but still poses a non‑negligible risk to confidentiality and integrity.

Generated by OpenCVE AI on September 3, 2026 at 10:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Blazy to version 3.0.19 or newer
  • Restrict or disable access to protected routes for unauthenticated and unprivileged users
  • Audit and tighten permission settings and access control configurations for content types and routes

Generated by OpenCVE AI on September 3, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Blazy Project
Blazy Project blazy
CPEs cpe:2.3:a:blazy_project:blazy:*:*:*:*:*:drupal:*:*
Vendors & Products Blazy Project
Blazy Project blazy

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal blazy
Vendors & Products Drupal
Drupal blazy

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.
Title Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T18:57:47.511Z

Reserved: 2026-08-26T16:19:46.916Z

Link: CVE-2026-81165

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T13:18:12.247

Modified: 2026-09-16T19:47:14.670

Link: CVE-2026-81165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:45:05Z

Weaknesses