Drupal Webform XSS (CVE-2026-96367): what site builders need to check first
Vulnerability overview
CVE-2026-96367 covers a cross-site scripting flaw in the Drupal contributed Webform module. The Drupal Security Team published advisory SA-CONTRIB-2026-162 on 2026-September-23. Its risk rating is Moderately critical, 13/25.
Mechanism and exploitation conditions
Webform lets site builders create forms, collect submissions, and configure access to forms and submission data. According to the advisory, the module does not sufficiently restrict access to the custom attributes YAML editor.
A user with permission to create or edit webforms, but without permission to edit webform source, may be able to add custom attributes, and that path leads to cross-site scripting.
The exploit path therefore starts with an authenticated role. The advisory states that an attacker must have a role with permission to create or edit webforms. The published vector is AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:Uncommon.
Impact
Script planted through the form editor then runs in another user's browser when that user views the affected form. The advisory lists cross-site scripting as the vulnerability class; the downstream effects depend on who views the page.
Affected products and scope
Webform versions below 6.2.12 are affected on the 6.2.x branch. On the 6.3.x branch, versions from 6.3.0 up to, but not including, 6.3.1 are affected.
Exposure context
A ZoomEye search for app="Drupal" returned 436,325 matching instances. This is a fingerprint count for Drupal assets, not a count of installations running the Webform module.
Remediation and mitigations
Move 6.2.x sites to Webform 6.2.12 and 6.3.x sites to Webform 6.3.1. If immediate patching is not possible, tighten the roles that can create or edit webforms and review who currently holds them.
References
- Drupal Security Advisory SA-CONTRIB-2026-162: https://www.drupal.org/sa-contrib-2026-162
- CERT-BUND advisory WID-SEC-2026-3554: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3554
Top comments (0)