DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden

CVE-2026-96365 and the Contribution Model: Why Drupal Site Owners Carry the Patch Burden

Vulnerability overview

CVE-2026-96365 belongs to WID-SEC-2026-3554, a CERT-BUND advisory published on 23 September 2026 and rated high risk. The advisory lists 36 identifiers, CVE-2026-96355 through CVE-2026-96398, and 16 contributed Drupal projects. Drupal core is not part of the advisory. Every affected component is a contributed project that a site owner chose to install.

Mechanism and exploitation conditions

The batch record describes remote exploitation with outcomes that include arbitrary code execution, extended privileges, bypass of security measures, data manipulation or disclosure, and cross-site scripting. It publishes no per-identifier flaw description, so the exploit mechanics for CVE-2026-96365 remain unspecified in this record. The practical precondition is possession of an affected module. Each contributed project runs inside the same request path as core, which is why a module without an obvious public page can still be reachable.

Impact

Sites that rely on contributed functionality absorb the risk directly. An unpatched module stays in the request path, and CERT-BUND rates both probability and damage at 4 out of 4 with a CVSS v3.1 base score of 9.8. The operational cost differs by project. Three maintainers shipped two fixed releases covering two supported branches, which shows the maintenance capacity behind each module varies.

Affected products and scope

Sixteen projects appear in the affected list. The fixed releases are Webform 6.2.12 and 6.3.1, Webform REST 4.2.1, Cloud 7.0.1, Project Browser 2.0.3 and 2.1.5, Commerce Decoupled Checkout 1.8.0, Mermaid Diagram Field 1.0.9, CookieCuttr 2.0.3, REST & JSON API Authentication 3.2.0, Stop administrator login 1.6, Tawk.to Live chat application 3.0.4, Editoria11y Accessibility Checker 2.2.23 and 3.0.9, AI CKEditor 1.4.3, Combined image style 1.0.7, CSS Usage Analyzer 1.0.2, Smart Content 3.2.1, and Diba carousel slider 3.0.2.

Exposure context

ZoomEye indexed 436403 assets matching app="Drupal" on 27 September 2026. That figure counts Drupal deployments rather than sites running one of these 16 modules. The companion query vul.cve="CVE-2026-96365" returned 0.

Remediation and mitigations

Inventory contributes more than patching speed here. Confirm which of the 16 projects you run, then update each to the fixed release on your branch. Where a project shipped two fixed versions, the older branch is the one that gets overlooked during a busy week. Routine maintenance should also track which contributed projects still receive security releases. A project that cannot publish a fix is a project to retire.

References

Top comments (0)