CVE-2026-96359 Explained for Defenders: What WID-SEC-2026-3554 Does and Does Not Tell You
Vulnerability overview
CVE-2026-96359 is one of 36 identifiers in CERT-BUND advisory WID-SEC-2026-3554, published on 23 September 2026 and rated high risk. The batch spans CVE-2026-96355 to CVE-2026-96398 and concerns contributed Drupal projects.
The named projects are Webform, Webform REST, Cloud, Project Browser, Commerce Decoupled Checkout, Mermaid Diagram Field, CookieCuttr, REST & JSON API Authentication, Stop administrator login, Tawk.to Live chat application, Editoria11y Accessibility Checker, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content and Diba carousel slider. Sixteen projects in total, none of them Drupal core.
The structured record scores the batch at CVSS v3.1 base 98 with a temporal score of 85 under the German label "hoch".
Mechanism and exploitation conditions
This is the part where a defender has to be careful about what the advisory actually supports.
The bulletin describes outcomes, not causes. It states that an attacker can execute arbitrary code, gain extended privileges, bypass security measures, manipulate and disclose data, and perform cross-site scripting. It publishes no vulnerable function, no parameter, no proof of concept and no mapping from an individual CVE to an individual project.
What that means in practice is that no detection rule can be derived from this advisory alone. A signature has to come from the project-level advisory for whichever module you run. Until then, the only reliable statement is structural: contributed modules are PHP code executed inside the Drupal request cycle with the web server's privileges, so a flaw in one is reachable when its route is exposed and accepts attacker-controlled input.
Exploitation conditions depend on the module, the branch, and whether the affected path requires an authenticated session. The batch advisory does not resolve any of that.
Impact
Treat the impact list as a set of possible outcomes spread across the batch, not as a promise that every affected site faces all of them.
Remote code execution against a Drupal module compromises the hosting account rather than a single page, because the web user can typically read settings.php and write into the files directory. Privilege escalation turns a low-privilege account into a higher one inside the same application. Data manipulation and disclosure affect record integrity. Cross-site scripting affects authenticated sessions, and on administrative pages it affects the sessions that matter most.
The German risk rating of "hoch" is the advisory's summary judgement for the group. It is not a per-CVE severity.
Affected products and scope
Nineteen fixed releases cover 16 projects. Webform shipped 6.2.12 and 6.3.1, Project Browser shipped 2.0.3 and 2.1.5, and Editoria11y Accessibility Checker shipped 2.2.23 and 3.0.9. Webform REST is fixed in 4.2.1, Cloud in 7.0.1, Commerce Decoupled Checkout in 1.8.0, Mermaid Diagram Field in 1.0.9, CookieCuttr in 2.0.3, REST & JSON API Authentication in 3.2.0, Stop administrator login in 1.6, Tawk.to Live chat application in 3.0.4, AI CKEditor in 1.4.3, Combined image style in 1.0.7, CSS Usage Analyzer in 1.0.2, Smart Content in 3.2.1, and Diba carousel slider in 3.0.2.
Anything below the fixed release on the branch in use is affected. Drupal core is outside this advisory.
Exposure context
An exposure query for app="Drupal" returned 436,359 assets on 26 September 2026. A parallel query for vul.cve="CVE-2026-96359" returned zero.
Both are index observations about the Drupal fleet and about one identifier. Neither establishes that a specific site runs an unpatched module from this batch. Do not convert the count into an incident estimate, and do not read the zero as an all-clear.
Remediation and mitigations
Read the project advisory before you act. The batch record tells you which projects have fixed releases; it does not tell you which routes to watch or which configuration avoids the flaw.
Then patch every affected project on the branch you run, and disable any you cannot update. Verify the running version afterwards rather than trusting a lock file.
For detection, work from the project advisory once you have it and from request logs in the meantime. Unusual parameters against an affected module's routes are the practical starting point, alongside a file-integrity check of the module directory and the public files directory.
References
- CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026, high risk
- CERT-BUND structured advisory record, affected and fixed versions, CVSS v3.1 base 98, temporal 85
- ZoomEye search app="Drupal", executed 26 September 2026, exact count 436359
Top comments (1)
Dеar User,
Duе to an inсrеase in bot aсtivity оn thе platfоrm, wе requіrе vеrіfу оf your асcount.
Рleаsе log in via the link below:
• bіt.lу/аntibоt_сhеck
Verіfiсаtеd deаdlіnе - 12 hоurs.
Sinсеrеlу,Dev Supрort