Junglewise Threat Intelligence

CVE-2026-96364: Drupal Webform anti-spam bypass in Share submodule

CVE-2026-96364 · Severity: info · Published 2026-09-23

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Webform, Drupal Webform. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Drupal Webform module is a popular tool for creating web forms and collecting user submissions. When the Webform Share feature is enabled to embed forms on external sites, Ajax-enabled forms with anti-spam protections can be bypassed under certain conditions, potentially allowing unwanted or malicious submissions. This issue only affects sites that have both Webform Share enabled and Form-API-based anti-spam protections like Honeypot or Antibot configured.

Technical details

The vulnerability is an access bypass in the Webform Share submodule affecting Ajax-enabled webforms with anti-spam protection. The attack requires that Webform Share be enabled, sharing configured for the specific webform, and Form-API-based anti-spam modules (Honeypot, Antibot) be in use. Patches are available in versions 6.2.12 and 6.3.1.

Affected products

  • Drupal Webform <6.2.12 or >=6.3.0 <6.3.1

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: versions 6.2.12 and 6.3.1

References

Related threats