PatchSiren

Blazy Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Blazy Project CVE published 2026-09-02

CVE-2026-81165

CVE-2026-81165 is an Incorrect Authorization vulnerability in Drupal Blazy, allowing Forceful Browsing. The issue affects Blazy versions from 0.0.0 to 3.0.18. The CVSS score is 5.3, and the severity is MEDIUM. This vulnerability could allow attackers to access unauthorized content. Defenders should assess potential browsing risks and verify version exposure. The CVE record and NVD entry provide details on [truncated]