DEV Community

kozhevniko
kozhevniko

Posted on

Why CVE-2026-96364 cannot be mapped to a single Drupal module from public records

Why CVE-2026-96364 cannot be mapped to a single Drupal module from public records

Vulnerability overview

CVE-2026-96364 appears in CERT-BUND advisory WID-SEC-2026-3554, published on 23 September 2026 and titled Drupal Erweiterungen: Mehrere Schwachstellen. The advisory covers 36 CVE identifiers across 16 contributed Drupal projects. It is rated high and carries a remotely exploitable flag with CVSS version 3.1 base score 98 and temporal score 85.
Searching for the identifier alone leads to a dead end. The NVD API returns zero results for it, and the MITRE CVE record is not yet published. The only machine-readable record available at the time of writing is the CERT-BUND advisory, and that record treats the 36 identifiers as a group.

Mechanism and exploitation conditions

The advisory does not publish a mechanism for CVE-2026-96364. It describes the batch outcomes as arbitrary code execution, extended privileges, bypassed security measures, data manipulation and disclosure, and cross-site scripting. No single identifier is tied to a code path, a request or a configuration state.
This is a reporting convention rather than a gap in the maintainers' work. The Drupal Security Team publishes per-project advisories as sa-contrib-2026-154 through sa-contrib-2026-191, and each of those names the project, the vulnerability class and the affected version range. CERT-BUND aggregated them into one national advisory for German-speaking operators, and the aggregation is what loses the one-to-one mapping.

Impact

The missing mapping has its main effect on prioritisation, not on the vulnerability itself. An operator who reads CVE-2026-96364 as a specific Drupal flaw will look for that flaw and find nothing. An operator who reads it as a pointer into a 36-identifier batch will go to the version table, list installed projects, and find the affected ones directly.

Affected products and scope

The batch names 16 contributed projects: Webform, Cloud, Project Browser, Commerce Decoupled Checkout, Mermaid Diagram Field, CookieCuttr, REST and JSON API Authentication, Stop administrator login, the Tawk.to live chat application, Editoria11y Accessibility Checker, Webform REST, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content and Diba carousel slider. Fixed releases include Webform 6.2.12 and 6.3.1, Cloud 7.0.1, Project Browser 2.0.3 and 2.1.5, and Editoria11y Accessibility Checker 2.2.23 and 3.0.9. The remaining projects have single-branch fixes: Commerce Decoupled Checkout 1.8.0, Mermaid Diagram Field 1.0.9, CookieCuttr 2.0.3, REST and JSON API Authentication 3.2.0, Stop administrator login 1.6, Tawk.to live chat 3.0.4, Webform REST 4.2.1, AI CKEditor 1.4.3, Combined image style 1.0.7, CSS Usage Analyzer 1.0.2, Smart Content 3.2.1 and Diba carousel slider 3.0.2.
Core is outside this advisory. Sites that only track core releases still need a contributed-module review.

Exposure context

A ZoomEye query for app="Drupal" returned 436388 matching assets on 27 September 2026. A query for vul.cve="CVE-2026-96364" returned zero, which reflects index coverage for that string rather than the absence of affected deployments.

Remediation and mitigations

Treat the identifier as an entry point. Pull the advisory, read the version table, and reconcile it against the site's installed projects. Update each affected project to its fixed release for the branch in use. Where the affected project is unused, remove it so the next batch is smaller. Where it is in use and cannot be updated immediately, disable it or restrict the affected routes. Verification means reading the installed version after the change, not the update log.

References

  • CERT-BUND advisory WID-SEC-2026-3554, Drupal extensions, 23 September 2026
  • Drupal Security Advisories sa-contrib-2026-154 through sa-contrib-2026-191, 23 September 2026
  • Drupal security advisories index
  • NVD CVE API query for CVE-2026-96364, no record published at query time

Top comments (0)