Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114
Project: Entity PDFDate: 2026-August-26Security risk: Moderately critical 13 ∕ 25 AC:None/A:User/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <2.1.5CVE IDs: CVE-2026-81164Description: The Entity PDF module can create a PDF from any entity based on any View mode.
This module does not check entity view access when fetching a PDF route. This could result in a user accessing a PDF of an entity that they should not be able to view.Solution: Install the latest version:
- If you use the Entity PDF module for Drupal upgrade to Entity PDF 2.1.5.
Reported By:
Fixed By:
Coordinated By:
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team

