DEV Community

kozhevniko
kozhevniko

Posted on

Cross-Site Scripting in the WID-SEC-2026-3554 Batch: The CVE-2026-96369 Angle

Cross-Site Scripting in the WID-SEC-2026-3554 Batch: The CVE-2026-96369 Angle

Vulnerability overview

CVE-2026-96369 is part of CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026 and rated high risk. The advisory carries 36 identifiers, CVE-2026-96355 to CVE-2026-96398, covering contributed Drupal projects. The structured record applies a CVSS v3.1 base score of 98 and a temporal score of 85 to the batch as a whole.
Among the impact classes the bulletin lists, cross-site scripting is the one most often dismissed on Drupal sites, and that dismissal is worth revisiting.

Mechanism and exploitation conditions

The advisory describes outcomes rather than mechanisms: arbitrary code execution, privilege escalation, security bypass, data manipulation and disclosure, and cross-site scripting. It publishes no vulnerable function, no parameter, and no per-identifier mapping to a project.
Contributed modules run as PHP inside the Drupal request cycle with the web server's privileges. A module that renders user-controlled content without adequate escaping is the general shape of an XSS issue, but the batch advisory does not confirm that this is what CVE-2026-96369 involves. That determination depends on the project-level advisory for the module in use.

Impact

XSS on an authenticated Drupal site is not the same problem as reflected XSS on a public blog. Session cookies for administrative users sit behind that boundary. A script executing in an administrator's browser can perform state-changing requests with that session, including actions the attacker could not reach directly.
The batch also lists outcomes beyond scripting, so treating the whole advisory as an XSS-only problem would be a misreading in the other direction. The point is that the scripting class deserves its own attention rather than being folded into the RCE discussion.

Affected products and scope

Sixteen projects with 19 fixed releases. Webform 6.2.12 and 6.3.1. Project Browser 2.0.3 and 2.1.5. Editoria11y Accessibility Checker 2.2.23 and 3.0.9. Webform REST 4.2.1. Cloud 7.0.1. Commerce Decoupled Checkout 1.8.0. Mermaid Diagram Field 1.0.9. CookieCuttr 2.0.3. REST & JSON API Authentication 3.2.0. Stop administrator login 1.6. Tawk.to Live chat application 3.0.4. AI CKEditor 1.4.3. Combined image style 1.0.7. CSS Usage Analyzer 1.0.2. Smart Content 3.2.1. Diba carousel slider 3.0.2.
Drupal core is outside this advisory.

Exposure context

ZoomEye returned 436,345 assets for app="Drupal" on 28 September 2026, and zero for vul.cve="CVE-2026-96369". The fleet count and the identifier count are index observations, not installation facts about any given site.

Remediation and mitigations

Move the sixteen projects to their fixed releases first, since that closes whatever issue CVE-2026-96369 represents along with the rest of the batch. Where a module cannot be updated, consider removing it, and check whether its functionality is actually in use before assuming it cannot go.
Harden the session side in parallel. Content Security Policy, where the site can support it, limits what an injected script can do. HttpOnly and SameSite attributes on session cookies reduce the value of a stolen session. Neither is a substitute for patching, and both reduce the blast radius while the patch is pending.
Review the administrative roles that can reach any of the affected module interfaces. Accounts with broad permissions are the ones an XSS payload would target.

References

  • CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026, high risk
  • CERT-BUND structured advisory record, affected and fixed versions, CVSS v3.1 base 98, temporal 85
  • ZoomEye search app="Drupal", executed 28 September 2026, exact count 436345

Top comments (0)