Detecting unexpected custom attributes after CVE-2026-96367
Vulnerability overview
SA-CONTRIB-2026-162 documents CVE-2026-96367, a cross-site scripting flaw in the Drupal contributed Webform module. Drupal published the advisory on 2026-September-23 and rated it Moderately critical at 13/25.
Mechanism and exploitation conditions
According to the advisory, the module does not sufficiently restrict access to the custom attributes YAML editor. A user holding permission to create or edit webforms, but not permission to edit webform source, may add custom attributes, which the module renders and which therefore lead to cross-site scripting.
Impact
The affected artifact is a stored configuration, not a one-time request, so injected content stays attached to the form. Detection therefore looks at form configuration and at the roles able to change it. The advisory names the attacker's role requirement as the limiting factor, and its vector is AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:Uncommon.
Affected products and scope
On 6.2.x, Webform releases below 6.2.12 are affected. On 6.3.x, releases from 6.3.0 up to but not including 6.3.1 are affected.
Exposure context
A ZoomEye search for app="Drupal" returned 436,325 instances. The number reflects the Drupal product fingerprint and cannot be read as a count of vulnerable Webform installations.
Remediation and mitigations
Install Webform 6.2.12 on the 6.2.x branch or Webform 6.3.1 on the 6.3.x branch. After patching, review form definitions for custom attributes that no administrator recognises and confirm that the create or edit webform permission is limited to roles that genuinely need it.
References
- Drupal Security Advisory SA-CONTRIB-2026-162: https://www.drupal.org/sa-contrib-2026-162
- CERT-BUND advisory WID-SEC-2026-3554: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3554
Top comments (0)