Mapping CVE-2026-96361 to the Drupal Projects You Actually Run
Vulnerability overview
CVE-2026-96361 is one identifier inside CERT-BUND advisory WID-SEC-2026-3554, published on 23 September 2026 and rated high risk. The advisory covers 16 contributed Drupal projects and 36 identifiers from CVE-2026-96355 to CVE-2026-96398.
Because the record spans so many projects, the first useful action is an inventory match rather than a reading of the whole list.
Mechanism and exploitation conditions
CERT-BUND records the batch as remotely exploitable and patched, and groups the outcomes as arbitrary code execution, extended privileges, bypass of security measures, data manipulation or disclosure, and cross-site scripting. It does not publish a per-identifier defect description.
Exposure therefore depends on module presence and reachability rather than on how alarming the identifier list looks. A site with none of the 16 projects installed has nothing to match.
Impact
When an affected module is present and reachable, the consequences are those the advisory describes: server-side code execution, privilege escalation, control bypass, data exposure or alteration, and script injection. Probability and damage are both scored 4 out of 4, with a CVSS v3.1 base score of 9.8 and a temporal score of 8.5.
Affected products and scope
The 16 projects and their fixed releases are Webform 6.2.12 and 6.3.1, Webform REST 4.2.1, Cloud 7.0.1, Project Browser 2.0.3 and 2.1.5, Commerce Decoupled Checkout 1.8.0, Mermaid Diagram Field 1.0.9, CookieCuttr 2.0.3, REST & JSON API Authentication 3.2.0, Stop administrator login 1.6, Tawk.to Live chat application 3.0.4, Editoria11y Accessibility Checker 2.2.23 and 3.0.9, AI CKEditor 1.4.3, Combined image style 1.0.7, CSS Usage Analyzer 1.0.2, Smart Content 3.2.1, and Diba carousel slider 3.0.2. Drupal core is outside the advisory.
Exposure context
ZoomEye indexed 436,344 assets matching app="Drupal" on 26 September 2026, which measures the Drupal population rather than confirmed vulnerable sites. A companion query for vul.cve="CVE-2026-96361" returned 0, so this identifier is not indexed as an exposed service.
Remediation and mitigations
Build the match list first. Export your installed contributed modules, compare that list with the 16 projects above, and record a version for each hit. Then update each hit to the fixed release on its branch and confirm the reported version afterwards.
A match list is also the artifact to keep, because the same export answers the next advisory faster than a fresh investigation would.
References
- CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026
- CERT-BUND structured record for WID-SEC-2026-3554, 16 projects and 19 fixed releases
- ZoomEye search app="Drupal", executed 26 September 2026, exact count 436344
Top comments (0)