Junglewise Threat Intelligence

CVE-2026-96388: Drupal Tawk.to module CSRF vulnerability

CVE-2026-96388 · Severity: info · Published 2026-09-23

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Tawk.to live chat integration module for Drupal sites fails to validate certain requests, allowing attackers to exploit a cross-site request forgery (CSRF) vulnerability. An attacker can trick an authenticated Drupal user into performing unintended actions, such as modifying site settings or account configurations, without the user's knowledge or consent.

Technical details

The module does not sufficiently validate CSRF tokens on certain requests, allowing unauthenticated attackers to forge requests on behalf of authenticated users. The vulnerability requires user interaction (tricking an authenticated admin or user into visiting a malicious page) but no additional privileges. Exploitation allows an attacker to perform administrative actions within the module context. The vulnerability is fixed in version 3.0.4.

Affected products

  • Drupal Tawk.to <3.0.4

Timeline

  • 2026-09-23: disclosed: DRUPAL-CONTRIB-2026-184 published

References