Executive brief
The Webform module for Drupal allows site builders to create forms and control who can view submissions. A flaw in how the module processes access rules could incorrectly grant anonymous users access to submissions that should only be visible to specific user accounts, but only if the access configuration is malformed. This could expose sensitive form submission data to unauthorized visitors.
Technical details
Webform did not sufficiently validate user-specific access rules against malformed saved configurations, allowing an access-control bypass where anonymous users could gain submission access intended only for selected authenticated accounts. The vulnerability requires site-specific conditions and depends on malformed saved access-rule configuration to be exploited. Fixes are available in versions 6.2.12 and 6.3.1.
Affected products
- Drupal Webform All versions prior to 6.2.12, and 6.3.0
Timeline
- 2026-09-23: disclosed