Junglewise Threat Intelligence

CVE-2026-81166: Drupal Digital Signage Framework access bypass via unprotected device refresh route

CVE-2026-81166 · Severity: medium · CVSS 5.3 · Published 2026-09-02

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Drupal Digital Signage Framework module manages content displays across multiple devices. A missing authorization check on a device refresh route allows unauthenticated visitors to read rendered content from blocks they should not have access to, potentially exposing sensitive information displayed on digital signage systems.

Technical details

The vulnerability is an access bypass (CWE-284: Missing Authorization) in the Digital Signage Framework module affecting versions before 2.6.1. A public route used by signage devices to refresh dynamic blocks fails to verify whether the requester is an authorized signage device or whether the requested block should be accessible, allowing anonymous attackers to retrieve rendered block content via forceful browsing. The impact is mitigated by the fact that many block plugins implement their own access controls, limiting disclosure. The fix requires updating to version 2.6.1 or later.

Affected products

  • Drupal Digital Signage Framework before 2.6.1

Timeline

  • 2026-08-26: disclosed: Security advisory published (SA-CONTRIB-2026-109)
  • 2026-08-19: patched: Version 2.6.1 released with fix
  • 2026-09-02: other: CVE-2026-81166 published

References