Executive brief
The Webform module for Drupal allows site builders to create and manage forms and collect user submissions with restricted access controls. A vulnerability in access control permits users who can view a submission to access more permissive view modes and see restricted fields they should not access. The risk is mitigated by the requirement that an attacker must already have legitimate access to view the affected submission.
Technical details
The Webform module does not sufficiently restrict access to certain submission view modes, allowing an authenticated user with submission viewing permissions to escalate to a more permissive view mode and access restricted fields. This is an access bypass vulnerability requiring prior submission access. Patches are available in versions 6.2.12 and 6.3.1.
Affected products
- Drupal Webform before 6.2.12 or 6.3.0 before 6.3.1
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Versions 6.2.12 and 6.3.1 released