Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113

Project: Entity APIDate: 2026-August-26Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Information disclosureAffected versions: <1.8.0CVE IDs: CVE-2026-81158Description: The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties.
The module doesn't correctly apply access controls for JSON:API entity collection endpoints. This exposes an information disclosure vulnerability.
This vulnerability is mitigated by the fact that the JSON:API module must be enabled in combination with the Entity API module.Solution: Install the latest version:

Reported By: 

Fixed By: 

Coordinated By: 

Path to article https://www.drupal.org/sa-contrib-2026-113