DEV Community

StarkMan
StarkMan

Posted on

CVE-2026-96362 and the Limits of Version-Based Drupal Scanning

CVE-2026-96362 and the Limits of Version-Based Drupal Scanning

Vulnerability overview

CERT-BUND advisory WID-SEC-2026-3554 covers a batch of vulnerabilities in contributed Drupal projects, published 23 September 2026 and rated high risk. The batch spans CVE-2026-96355 to CVE-2026-96398 and contains 36 identifiers, with CVE-2026-96362 among them.
The subject is contributed code. Externally visible Drupal installations usually reveal the platform, and sometimes detectable modules, but rarely the full internal module inventory.

Exposure context

A ZoomEye query for app="Drupal" returned 436349 assets on 26 September 2026, while vul.cve="CVE-2026-96362" returned 0.
The first figure shows how many Drupal deployments an internet-wide index can see. It does not show which of them carry a module from this batch. The second figure reflects index coverage for one identifier and cannot be read as proof that no site is affected. Both numbers describe what is observable from outside, not what runs inside a given site.

Mechanism and exploitation conditions

The advisory states consequences for the batch together: arbitrary code execution, extended privileges, bypassed security controls, manipulated and disclosed data, and cross-site scripting. It publishes no per-CVE root cause, proof of concept or route list.
Contributed modules are PHP inside the Drupal request cycle, normally with web server privileges. Reachability turns on whether an anonymous or low-privilege visitor can reach the vulnerable controller, form or AJAX callback and whether attacker-controlled input reaches an unprotected sink.

Impact

Code execution and privilege escalation can carry an attacker past the affected module into the hosting account, with settings.php holding database credentials that web-user code can often read. Data manipulation and disclosure affect compliance, and cross-site scripting reaches authenticated sessions, administrators included.

Affected products and scope

The structured record names 16 projects and 19 fixed versions.

  • Webform: fixed in 6.2.12 and 6.3.1
  • Webform REST: fixed in 4.2.1
  • Cloud: fixed in 7.0.1
  • Project Browser: fixed in 2.0.3 and 2.1.5
  • Commerce Decoupled Checkout: fixed in 1.8.0
  • Mermaid Diagram Field: fixed in 1.0.9
  • CookieCuttr: fixed in 2.0.3
  • REST & JSON API Authentication: fixed in 3.2.0
  • Stop administrator login: fixed in 1.6
  • Tawk.to Live chat application: fixed in 3.0.4
  • Editoria11y Accessibility Checker: fixed in 2.2.23 and 3.0.9
  • AI CKEditor: fixed in 1.4.3
  • Combined image style: fixed in 1.0.7
  • CSS Usage Analyzer: fixed in 1.0.2
  • Smart Content: fixed in 3.2.1
  • Diba carousel slider: fixed in 3.0.2 Drupal core is absent from the list, and any version below the fixed release on the installed branch remains affected.

Remediation and mitigations

Operators should rely on an internal inventory rather than external scanning to decide exposure. Compare installed contributed modules against the 16 projects and update to the fixed version for the branch in use, reading the project advisory where two fixed releases exist.
Disabled modules remove their routes from the request cycle when an update cannot be scheduled. In practice, verification should check the running code, because Drupal caching and container reuse can leave a fixed version string over unpatched files, and a scanner reading that string would report a clean state that does not exist.

References

Top comments (0)