Executive brief
The Drupal Webform module is a popular tool for creating web forms and collecting user submissions. When the Webform Share feature is enabled to embed forms on external sites, Ajax-enabled forms with anti-spam protections can be bypassed under certain conditions, potentially allowing unwanted or malicious submissions. This issue only affects sites that have both Webform Share enabled and Form-API-based anti-spam protections like Honeypot or Antibot configured.
Technical details
The vulnerability is an access bypass in the Webform Share submodule affecting Ajax-enabled webforms with anti-spam protection. The attack requires that Webform Share be enabled, sharing configured for the specific webform, and Form-API-based anti-spam modules (Honeypot, Antibot) be in use. Patches are available in versions 6.2.12 and 6.3.1.
Affected products
- Drupal Webform <6.2.12 or >=6.3.0 <6.3.1
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: versions 6.2.12 and 6.3.1