Junglewise Threat Intelligence

CVE-2026-96380: Drupal CSS Usage Analyzer improper access control on save endpoint

CVE-2026-96380 · Severity: info · Published 2026-09-23

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The CSS Usage Analyzer module for Drupal is a tool that allows frontend scanners to submit CSS-usage statistics to be displayed in admin reports. The module fails to properly validate or restrict submissions to its `/css-usage-analyzer/save` endpoint, allowing attackers to forge or replay measurements and potentially corrupt analytics data or manipulate site statistics.

Technical details

This is an improper access control vulnerability in the CSS Usage Analyzer module's `/css-usage-analyzer/save` endpoint, which does not sufficiently validate incoming requests against forged or repeated submissions. The endpoint is likely unauthenticated or insufficiently protected, allowing an attacker with network access to POST arbitrary or replayed measurement data. A successful exploit can lead to injection of false CSS-usage metrics, data integrity issues in reports, or potential denial-of-service through repeated submissions.

Affected products

  • Drupal CSS Usage Analyzer 1.0.0 to 1.0.1

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Fixed in version 1.0.2

References