DEV Community

StarkMan
StarkMan

Posted on

Drupal's September 2026 Contrib Batch: Where CVE-2026-96366 Sits in a 36-CVE Advisory

Drupal's September 2026 Contrib Batch: Where CVE-2026-96366 Sits in a 36-CVE Advisory

Contributed module advisories rarely arrive one at a time, and September 2026 was no exception. Understanding where a single CVE sits inside a batch helps decide whether it needs its own change window.

Vulnerability overview

CVE-2026-96366 is an access bypass in the Webform contributed module. It appears in SA-CONTRIB-2026-169, dated 2026-09-23 and rated moderately critical at 12/25, and also within CERT-BUND's WID-SEC-2026-3554 batch advisory covering 36 CVE identifiers across 16 contributed Drupal projects.

Mechanism and exploitation conditions

The advisory records that Webform did not sufficiently validate a managed file upload element during submission processing. A user allowed to submit a vulnerable form could reach managed files outside their authorisation. The site must have a webform with a managed file upload element and a configuration that exposes submitted files, for instance a setting letting users view their own submissions or an email handler that attaches uploads.

Impact

Unauthorised reading of managed files is the described effect, with confidentiality marked as some and no integrity or availability impact. Within the batch, this places the flaw in a different operational category from projects where code execution or privilege escalation was possible, even though the batch shares one severity headline.

Affected products and scope

Webform below 6.2.12 and 6.3.0 up to 6.3.1 are affected; 6.2.12 and 6.3.1 are fixed. Other projects named in the same batch, including Webform REST, Editoria11y Accessibility Checker, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content, and Diba carousel slider, carry their own CVE identifiers and are not addressed by the Webform upgrade.

Exposure context

ZoomEye returned 436,370 matches for app="Drupal" on 2026-09-27 and none for vul.cve="CVE-2026-96366". Census counts describe the platform, not the module set inside it, which is exactly why batch advisories need per-project inventories rather than a single triage pass.

Remediation and mitigations

Patch Webform to 6.2.12 or 6.3.1 and run the update path. Then walk the rest of the batch: list affected contributed projects, mark which are installed, and redeem the fixed versions from the CERT-BUND record. For Webform specifically, review submission visibility and attachment delivery so that hardening survives future configuration changes.

References

Top comments (0)