DEV Community

yutianle
yutianle

Posted on

CVE-2026-96364 in the patch pipeline: dependency order for 16 Drupal projects

CVE-2026-96364 in the patch pipeline: dependency order for 16 Drupal projects

Vulnerability overview

CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026, carries CVE-2026-96364 inside a set of 36 identifiers that affect 16 contributed Drupal projects. The rating is high, the affected systems are flagged remotely exploitable, and the score block cites CVSS version 3.1 base score 98 with temporal score 85. Fixed releases exist for the listed projects, since the record reports noPatch as false.

Vulnerability overview in engineering terms

A batch like this does not land in a maintenance window as a single change. Sixteen projects means sixteen dependency decisions, and several of them affect each other through Composer constraints, shared libraries and configuration entities that reference each other's fields.

Mechanism and exploitation conditions

The batch record does not describe how CVE-2026-96364 is triggered, and it associates no individual mechanism with any identifier in the set. It states the outcome classes: arbitrary code execution, privilege escalation, bypassing security measures, data manipulation and disclosure, and cross-site scripting. The trigger detail belongs to the per-project advisory.
The engineering consequence is that the pipeline has to absorb a security-driven update without a mechanism description to prioritise from, which pushes prioritisation onto reachability and dependency risk instead.

Impact

Sequencing mistakes are the main risk here. Updating a base module before a dependent one can leave the dependent module on a version range that no longer exists. Updating a module that owns fields before the modules that render those fields can produce configuration import failures that stall a deployment mid-window. Both outcomes extend exposure time rather than reduce it.

Affected products and scope

Affected projects: Webform, Cloud, Project Browser, Commerce Decoupled Checkout, Mermaid Diagram Field, CookieCuttr, REST and JSON API Authentication, Stop administrator login, Tawk.to live chat, Editoria11y Accessibility Checker, Webform REST, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content and Diba carousel slider. Fixed releases: Webform 6.2.12 and 6.3.1, Cloud 7.0.1, Project Browser 2.0.3 and 2.1.5, Commerce Decoupled Checkout 1.8.0, Mermaid Diagram Field 1.0.9, CookieCuttr 2.0.3, REST and JSON API Authentication 3.2.0, Stop administrator login 1.6, Tawk.to live chat 3.0.4, Editoria11y Accessibility Checker 2.2.23 and 3.0.9, Webform REST 4.2.1, AI CKEditor 1.4.3, Combined image style 1.0.7, CSS Usage Analyzer 1.0.2, Smart Content 3.2.1 and Diba carousel slider 3.0.2. Core is not part of this advisory.

Exposure context

ZoomEye returned 436388 matches for app="Drupal" on 27 September 2026 and none for the exact CVE string. The number is a reminder that small sequencing delays on internet-facing Drupal correlate with a large exposed population.

Remediation and mitigations

Order the work as follows. First, capture the current Composer lock or module list as a rollback point. Second, update leaf modules that nothing else depends on. Third, update modules that other installed modules declare a dependency on. Fourth, update the modules that own configuration and fields, and run a configuration import check. Fifth, verify installed versions from the status report and run the site's own smoke tests. Where a module cannot be updated in the window, disable it or restrict its routes, and log the deferral.

References

  • CERT-BUND advisory WID-SEC-2026-3554, Drupal extensions, 23 September 2026
  • Drupal Security Advisories sa-contrib-2026-154 through sa-contrib-2026-191, 23 September 2026
  • Drupal security advisories index

Top comments (0)