Why stored XSS in Drupal Webform (CVE-2026-96367) reaches other users
Vulnerability overview
The Drupal Security Team published CVE-2026-96367 as SA-CONTRIB-2026-162 on 2026-September-23. The vulnerability is cross-site scripting in the contributed Webform module, rated Moderately critical with 13/25.
Mechanism and exploitation conditions
Webform lets site builders create forms, collect submissions, and configure access to forms and submission data. The advisory says access to the custom attributes YAML editor is not sufficiently restricted. A user with permission to create or edit webforms, but without permission to edit webform source, may therefore add custom attributes, and the module renders them, producing cross-site scripting.
The attacker's entry point is an editor role, not an anonymous visitor. The advisory identifies that role requirement as the factor limiting the issue. The vector is AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:Uncommon.
Impact
Because the injected attributes belong to a stored form configuration, the injected script is served to later visitors rather than only to the person who added it. A limited editor permission therefore becomes a problem for other accounts, including privileged ones that open the form.
Affected products and scope
Webform below 6.2.12 is affected on the 6.2.x branch. On the 6.3.x branch, releases from 6.3.0 up to but not including 6.3.1 are affected.
Exposure context
ZoomEye returned 436,325 instances for app="Drupal". The result counts Drupal assets by product fingerprint and does not indicate whether Webform is installed or which version runs.
Remediation and mitigations
Install Webform 6.2.12 for the 6.2.x line or Webform 6.3.1 for the 6.3.x line. Until the update is deployed, restrict the create or edit webform permission to the smallest set of roles that need it, and review form configurations for unexpected custom attributes.
References
- Drupal Security Advisory SA-CONTRIB-2026-162: https://www.drupal.org/sa-contrib-2026-162
- CERT-BUND advisory WID-SEC-2026-3554: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3554
Top comments (0)