Drupal Contributed Modules Under WID-SEC-2026-3554: A Patching Plan for CVE-2026-96359 and the Wider Batch
Vulnerability overview
CVE-2026-96359 belongs to a group of 36 identifiers published as CERT-BUND advisory WID-SEC-2026-3554 on 23 September 2026. The advisory is rated high risk and covers contributed Drupal projects rather than core.
The record lists 36 CVE identifiers, CVE-2026-96355 through CVE-2026-96398, against a set of add-on projects. The German-language summary states that an attacker can exploit the flaws to run arbitrary code, escalate privileges, bypass protections, alter and expose data, and inject script into pages. It does not separate those outcomes by identifier.
CVSS v3.1 scoring in the structured record gives the batch a base score of 98 and a temporal score of 85, classified "hoch". Those figures describe the batch, not a single module.
Mechanism and exploitation conditions
The advisory reports impact classes, not root causes. There is no published description of a faulty function, a vulnerable parameter, or the request that triggers a specific flaw.
That absence has a direct operational consequence. You cannot reason from the CVE number to a detection signature. The reachable surface depends on which project is enabled, which routes that project exposes, and whether the flaw requires an authenticated session.
What can be said with confidence is structural. Contributed modules are PHP code loaded into the Drupal request cycle. They run with the web server's privileges. A flaw in one of them is exploitable when the affected route is reachable and the module places attacker-controlled input where PHP later acts on it. Precisely which of the 36 identifiers meets that description, and under which configuration, has to come from the project's own advisory.
Impact
The impact list mixes severities that should not be handled the same way. Remote code execution and privilege escalation can turn a content-management problem into a hosting-account compromise. Data manipulation and disclosure affect record integrity and may trigger notification duties. Cross-site scripting affects authenticated users, and on an administrative page that includes privileged sessions.
For a site running several of the affected projects, the practical risk is not one of these outcomes but the combination. A code-execution flaw in one module can be chained with a session-level flaw in another, and both would sit in the same batch.
Affected products and scope
Sixteen contributed projects are listed with fixed versions. Nineteen fixed releases appear in the record because some projects published more than one.
Webform is fixed in 6.2.12 and 6.3.1. Project Browser is fixed in 2.0.3 and 2.1.5. Editoria11y Accessibility Checker is fixed in 2.2.23 and 3.0.9. Webform REST is fixed in 4.2.1, Cloud in 7.0.1, Commerce Decoupled Checkout in 1.8.0, Mermaid Diagram Field in 1.0.9, CookieCuttr in 2.0.3, REST & JSON API Authentication in 3.2.0, Stop administrator login in 1.6, Tawk.to Live chat application in 3.0.4, AI CKEditor in 1.4.3, Combined image style in 1.0.7, CSS Usage Analyzer in 1.0.2, Smart Content in 3.2.1, and Diba carousel slider in 3.0.2.
Affected scope is every installation below the fixed release on the branch in use. Drupal core is outside this advisory.
Exposure context
An exposure query on 26 September 2026 for app="Drupal" returned 436,359 assets. A query for vul.cve="CVE-2026-96359" returned zero.
Read both as index observations. The first shows how many Drupal deployments are visible and therefore how large the search space is for anyone looking for an unpatched extension. The second shows that this particular identifier is not indexed as an exposed service. Neither number identifies a vulnerable site.
Remediation and mitigations
Build a version inventory per site before patching. Export the list of installed contributed projects from the site, then compare each entry against the fixed releases above.
Sequence the work by module role. Anything that touches authentication, API access or stored content deserves the first slot, because those modules sit closest to the impact classes in the advisory. Presentation-layer modules can wait, but they should not be forgotten: cross-site scripting still lands in that group.
Update, then disable or remove modules that have no maintained fixed release for the branch you run. Confirm the update reached production by checking the running version, not the composer lock file alone.
References
- CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026, high risk, 36 CVE identifiers
- CERT-BUND structured advisory record with affected and fixed versions for 16 contributed projects
- ZoomEye search app="Drupal", executed 26 September 2026, exact count 436359
Top comments (0)