Description
Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Resource Access
Action: Patch Immediately
AI Analysis

Impact

Drupal Digital Signage Framework suffers from a missing authorization flaw that allows forceful browsing of protected configuration endpoints. Because the system does not enforce proper permissions on these sensitive pages, an attacker who can reach them—whether authenticated with minimal privileges or unauthenticated—can request and retrieve configuration data that should be restricted. The weakness, cataloged as CWE-862, enables unauthorized disclosure of potentially confidential layout or content settings, compromising the integrity of the signage delivery pipeline.

Affected Systems

The vulnerability affects all releases of the Digital Signage Framework from 0.0.0 through 2.6.1, as reported by the vendor’s security advisory. It applies to installations of the module within Drupal deployments that have not been updated beyond version 2.6.1.

Risk and Exploitability

The EPSS score is not provided, and the vulnerability is not currently listed in the CISA KEV catalog, which suggests that publicly known exploitation has not been observed. However, the flaw allows an attacker who can reach the affected endpoints to perform forceful browsing, a low-barrier privilege escalation that can be leveraged to expose configuration data. Without enforced authentication checks in place, the attack vector is likely HTTP or HTTPS requests to protected URIs, which can be executed from outside the trusted network if the endpoints are publicly accessible. The CVSS score of 5.3 indicates a moderate risk; while the exploit is straightforward, the potential exposure of sensitive configuration data may impact business operations.

Generated by OpenCVE AI on September 3, 2026 at 10:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Digital Signage Framework to a version beyond 2.6.1 that includes the authorization fix.
  • Review and tighten Drupal permission settings, ensuring that only trusted roles can access configuration and administration pages.
  • Configure IP whitelisting or application‑level access controls for sensitive configuration endpoints until the upgrade is completed.

Generated by OpenCVE AI on September 3, 2026 at 10:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Lakedrops
Lakedrops digital Signage Framework
CPEs cpe:2.3:a:lakedrops:digital_signage_framework:*:*:*:*:*:drupal:*:*
Vendors & Products Lakedrops
Lakedrops digital Signage Framework

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal digital Signage Framework
Vendors & Products Drupal
Drupal digital Signage Framework

Wed, 02 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.
Title Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-2026-109
Weaknesses CWE-862
References

Subscriptions

Drupal Digital Signage Framework
Lakedrops Digital Signage Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T19:06:25.649Z

Reserved: 2026-08-26T16:19:47.866Z

Link: CVE-2026-81166

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T13:18:12.357

Modified: 2026-09-16T19:45:24.063

Link: CVE-2026-81166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T11:00:03Z

Weaknesses