DEV Community

kozhevniko
kozhevniko

Posted on

Why stored XSS in Drupal Webform (CVE-2026-96367) reaches other users

Why stored XSS in Drupal Webform (CVE-2026-96367) reaches other users

Vulnerability overview

The Drupal Security Team published CVE-2026-96367 as SA-CONTRIB-2026-162 on 2026-September-23. The vulnerability is cross-site scripting in the contributed Webform module, rated Moderately critical with 13/25.

Mechanism and exploitation conditions

Webform lets site builders create forms, collect submissions, and configure access to forms and submission data. The advisory says access to the custom attributes YAML editor is not sufficiently restricted. A user with permission to create or edit webforms, but without permission to edit webform source, may therefore add custom attributes, and the module renders them, producing cross-site scripting.
The attacker's entry point is an editor role, not an anonymous visitor. The advisory identifies that role requirement as the factor limiting the issue. The vector is AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:Uncommon.

Impact

Because the injected attributes belong to a stored form configuration, the injected script is served to later visitors rather than only to the person who added it. A limited editor permission therefore becomes a problem for other accounts, including privileged ones that open the form.

Affected products and scope

Webform below 6.2.12 is affected on the 6.2.x branch. On the 6.3.x branch, releases from 6.3.0 up to but not including 6.3.1 are affected.

Exposure context

ZoomEye returned 436,325 instances for app="Drupal". The result counts Drupal assets by product fingerprint and does not indicate whether Webform is installed or which version runs.

Remediation and mitigations

Install Webform 6.2.12 for the 6.2.x line or Webform 6.3.1 for the 6.3.x line. Until the update is deployed, restrict the create or edit webform permission to the smallest set of roles that need it, and review form configurations for unexpected custom attributes.

References

Top comments (0)