Description
Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.
Published: 2026-09-02
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Drupal Blazy an incorrect Authorization vulnerability that enables forceful browsing. An attacker can craft requests to resources that should be restricted, thereby gaining unauthorized access to content or functionality that is otherwise protected by the system's permissions logic. The weakness is modeled by CWE-863 and results in a direct breach of access control.

Affected Systems

Drupal Blazy users running any version from 0.0.0 up to and including 3.0.18 are affected. The issue does not apply to versions released after 3.0.18.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests it may not be widely exploited yet. However, the Attack vector is inferred to be remote via HTTP requests targeting protected routes, and the exploit requires only knowledge of the resource identifier and the ability to send a request. Because the vulnerability allows bypassing Authorization checks, the potential impact includes unauthorized data exposure and possible escalation to higher privilege activities. The lack of a published CVSS score limits precise severity assessment, but the nature of the flaw indicates a non‑negligible risk to confidentiality and integrity.

Generated by OpenCVE AI on September 2, 2026 at 13:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Blazy to version 3.0.19 or newer
  • Restrict or disable access to protected routes for unauthenticated and unprivileged users
  • Audit and tighten permission settings and access control configurations for content types and routes

Generated by OpenCVE AI on September 2, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.
Title Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T12:32:14.458Z

Reserved: 2026-08-26T16:19:46.916Z

Link: CVE-2026-81165

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T13:18:12.247

Modified: 2026-09-02T13:53:45.597

Link: CVE-2026-81165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:30:05Z

Weaknesses