Junglewise Threat Intelligence

CVE-2026-96372: Drupal Webform module insufficient access restriction on remote HTTP operations

CVE-2026-96372 · Severity: info · Published 2026-09-23

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Webform, Drupal Webform. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Webform module for Drupal enables site builders to create forms and collect submissions. The module does not sufficiently restrict access to configure Remote HTTP Operations handlers, allowing a user with webform editing permissions to configure remote HTTP operations without proper authorization. This could allow attackers with webform editing access to redirect form submissions to arbitrary servers, exposing form data or enabling reconnaissance of internal systems.

Technical details

The vulnerability is an authorization bypass affecting the Remote HTTP Operations feature in the Webform module. A user with permission to edit a webform can configure remote HTTP operations without the new "Administer webform remote post URLs" permission, allowing them to send form submissions to attacker-controlled endpoints. The vulnerability requires the attacker to already have the role permission to edit webforms, which mitigates exposure but remains a privilege escalation concern within authenticated contexts.

Affected products

  • Drupal Webform <6.2.12 or >=6.3.0, <6.3.1

Timeline

  • 2026-09-23: disclosed

References

Related threats