DEV Community

kozhevniko
kozhevniko

Posted on

CVE-2026-96358: A Module Inventory Checklist from the CERT-BUND Record

CVE-2026-96358: A Module Inventory Checklist from the CERT-BUND Record

Vulnerability overview

CVE-2026-96358 belongs to CERT-BUND advisory WID-SEC-2026-3554, a high-risk advisory released on 23 September 2026 for multiple flaws in Drupal contributed modules. CERT-BUND flags the issues as remotely exploitable and records that fixes exist.

Mechanism and exploitation conditions

The advisory's shared impact sentence says an attacker can use the flaws to execute arbitrary code, gain elevated privileges, bypass security measures, tamper with and disclose data, or conduct cross-site scripting attacks. Because the sentence covers the whole batch, the exact behaviour depends on the individual module.

A worked inventory check

Start from the installed project list and its versions, then test each entry against the record:

  • Webform below 6.2.12 or below 6.3.1, fixed in 6.2.12 and 6.3.1
  • Project Browser below 2.0.3 or below 2.1.5, fixed in 2.0.3 and 2.1.5
  • Editoria11y Accessibility Checker below 2.2.23 or below 3.0.9, fixed in 2.2.23 and 3.0.9
  • Cloud below 7.0.1, fixed in 7.0.1
  • Commerce Decoupled Checkout below 1.8.0, fixed in 1.8.0
  • Mermaid Diagram Field below 1.0.9, fixed in 1.0.9
  • CookieCuttr below 2.0.3, fixed in 2.0.3
  • Stop administrator login below 1.6, fixed in 1.6
  • Tawk.to-Live chat application below 3.0.4, fixed in 3.0.4
  • Webform REST below 4.2.1, fixed in 4.2.1
  • AI CKEditor below 1.4.3, fixed in 1.4.3
  • Combined image style below 1.0.7, fixed in 1.0.7
  • CSS Usage Analyzer below 1.0.2, fixed in 1.0.2
  • Smart Content below 3.2.1, fixed in 3.2.1
  • Diba carousel slider below 3.0.2, fixed in 3.0.2 Projects that appear twice need their branch identified before the correct fixed release is chosen.

Affected products and scope

The record carries 19 ranges across 16 projects, with cpe:/a:drupal:drupal and platforms Linux, UNIX, Windows and other.

Impact

A site that finds an in-range project in its inventory has a concrete update to plan. A site that does not has evidence that this advisory batch does not apply to it.

Exposure context

ZoomEye returned 436276 matches for app="Drupal" on 25 September 2026 and zero for vul.cve="CVE-2026-96358". The product count is context, not a vulnerable-host count.

Remediation and mitigations

Update in-range projects to their fixed releases, then re-list installed versions. If a module inventory does not exist yet, creating one is the first corrective step.

References

  • CERT-BUND advisory WID-SEC-2026-3554 with the affected and fixed ranges
  • CERT-BUND structured advisory record for WID-SEC-2026-3554
  • ZoomEye query app="Drupal", checked 25 September 2026

Top comments (0)