Junglewise Threat Intelligence

CVE-2026-96356: Drupal Webform access control bypass with malformed configuration

CVE-2026-96356 · Severity: info · Published 2026-09-23

Technologies: Drupal Webform, Packagist:Https://Packages.Drupal.Org/8 Drupal/Webform. Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The Webform module for Drupal allows site builders to create forms and control who can view submissions. A flaw in how the module processes access rules could incorrectly grant anonymous users access to submissions that should only be visible to specific user accounts, but only if the access configuration is malformed. This could expose sensitive form submission data to unauthorized visitors.

Technical details

Webform did not sufficiently validate user-specific access rules against malformed saved configurations, allowing an access-control bypass where anonymous users could gain submission access intended only for selected authenticated accounts. The vulnerability requires site-specific conditions and depends on malformed saved access-rule configuration to be exploited. Fixes are available in versions 6.2.12 and 6.3.1.

Affected products

  • Drupal Webform All versions prior to 6.2.12, and 6.3.0

Timeline

  • 2026-09-23: disclosed

References

Related threats