Improper access control in Digital Signage Framework - CVE-2026-81166
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the route does not check whether the requester is a signage device, nor whether the requested block is one that the module delivers to displays. A remote attacker can gain access to sensitive information on the system.