PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81165 Blazy Project CVE debrief

CVE-2026-81165 is an Incorrect Authorization vulnerability in Drupal Blazy, allowing Forceful Browsing. The issue affects Blazy versions from 0.0.0 to 3.0.18. The CVSS score is 5.3, and the severity is MEDIUM. This vulnerability could allow attackers to access unauthorized content. Defenders should assess potential browsing risks and verify version exposure. The CVE record and NVD entry provide details on the vulnerability and affected versions, but additional verification is necessary to confirm exposure.

Vendor
Blazy Project
Product
Blazy
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-16
Advisory published
2026-09-02
Advisory updated
2026-09-16

Who should care

Defenders responsible for Drupal installations with Blazy versions from 0.0.0 to 3.0.18 should assess potential browsing risks and verify version exposure.

Why it matters

CVE-2026-81165 is a MEDIUM-severity vulnerability in Drupal Blazy, allowing Forceful Browsing. Defenders should prioritize verifying Blazy version exposure and assessing potential browsing risks.

  • Verify Blazy version exposure to prevent potential browsing risks
  • Assess browsing risks due to incorrect authorization

Technical summary

The vulnerability allows Forceful Browsing due to incorrect authorization in Drupal Blazy versions from 0.0.0 to 3.0.18. This could enable attackers to access unauthorized content. The CVSS score of 5.3 indicates a MEDIUM severity level. Defenders should prioritize verifying Blazy version exposure and assessing potential browsing risks. The technical details indicate a need for careful review of system configurations and version updates.

Defensive priority

Defenders should prioritize verifying Blazy version exposure and assessing potential browsing risks.

Recommended defensive actions

  • Verify Blazy version exposure
  • Assess potential browsing risks
  • Update Blazy to version 3.0.19 or later

Evidence notes

The CVE record and NVD entry provide details on the vulnerability and affected versions. However, defenders need to verify Blazy version exposure and assess potential browsing risks. The evidence is limited, and further review of affected systems is required. Additional sources, such as vendor advisories, should be consulted to confirm the vulnerability's impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81165 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81165

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81165 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81165

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.