Executive brief
The Webform module for Drupal, used to create forms and collect user submissions, fails to properly validate file uploads in certain configurations. An authenticated user could exploit this to access files uploaded by other users that they should not have permission to view, such as through viewing shared submissions or email attachments.
Technical details
The vulnerability exists in managed file upload element validation when processing new webform submissions. An attacker with form submission access can bypass file access controls to view files uploaded by other users. This requires specific site configuration (file-sharing features enabled, such as user-viewable submissions or email attachment handlers).
Affected products
- Drupal Webform before 6.2.12, and 6.3.0 before 6.3.1
Timeline
- 2026-09-23: disclosed