CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden
Vulnerability overview
CVE-2026-96365 belongs to WID-SEC-2026-3554, a CERT-BUND advisory published on 23 September 2026 and rated high risk. The advisory lists 36 identifiers, CVE-2026-96355 through CVE-2026-96398, and 16 contributed Drupal projects. Drupal core is not part of the advisory. Every affected component is a contributed project that a site owner chose to install.
Mechanism and exploitation conditions
The batch record describes remote exploitation with outcomes that include arbitrary code execution, extended privileges, bypass of security measures, data manipulation or disclosure, and cross-site scripting. It publishes no per-identifier flaw description, so the exploit mechanics for CVE-2026-96365 remain unspecified in this record. The practical precondition is possession of an affected module. Each contributed project runs inside the same request path as core, which is why a module without an obvious public page can still be reachable.
Impact
Sites that rely on contributed functionality absorb the risk directly. An unpatched module stays in the request path, and CERT-BUND rates both probability and damage at 4 out of 4 with a CVSS v3.1 base score of 9.8. The operational cost differs by project. Three maintainers shipped two fixed releases covering two supported branches, which shows the maintenance capacity behind each module varies.
Affected products and scope
Sixteen projects appear in the affected list. The fixed releases are Webform 6.2.12 and 6.3.1, Webform REST 4.2.1, Cloud 7.0.1, Project Browser 2.0.3 and 2.1.5, Commerce Decoupled Checkout 1.8.0, Mermaid Diagram Field 1.0.9, CookieCuttr 2.0.3, REST & JSON API Authentication 3.2.0, Stop administrator login 1.6, Tawk.to Live chat application 3.0.4, Editoria11y Accessibility Checker 2.2.23 and 3.0.9, AI CKEditor 1.4.3, Combined image style 1.0.7, CSS Usage Analyzer 1.0.2, Smart Content 3.2.1, and Diba carousel slider 3.0.2.
Exposure context
ZoomEye indexed 436403 assets matching app="Drupal" on 27 September 2026. That figure counts Drupal deployments rather than sites running one of these 16 modules. The companion query vul.cve="CVE-2026-96365" returned 0.
Remediation and mitigations
Inventory contributes more than patching speed here. Confirm which of the 16 projects you run, then update each to the fixed release on your branch. Where a project shipped two fixed versions, the older branch is the one that gets overlooked during a busy week. Routine maintenance should also track which contributed projects still receive security releases. A project that cannot publish a fix is a project to retire.
References
- CERT-BUND advisory WID-SEC-2026-3554, published 23 September 2026: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3554
- CERT-BUND structured record for WID-SEC-2026-3554, 16 projects and 19 fixed releases: https://wid.cert-bund.de/content/public/content/3f0df5d6-5291-41b3-92f2-0c016281c91f
- ZoomEye search app="Drupal", executed 27 September 2026, exact count 436403: https://www.zoomeye.ai/searchResult?q=YXBwPSJEcnVwYWwi
Top comments (0)