DEV Community

StarkMan
StarkMan

Posted on

Inventory Work for CVE-2026-96357: Finding Affected Drupal Modules First

Inventory Work for CVE-2026-96357: Finding Affected Drupal Modules First

Start with the inventory

Patching for CVE-2026-96357 cannot begin until the installed contributed modules are known. CERT-BUND advisory WID-SEC-2026-3554 lists 16 projects across 19 affected version ranges, and that list is the comparison set.

Vulnerability overview

The advisory was published on 23 September 2026 and rated high risk, with a CVSS v3.1 base score of 9.8 and temporal score of 8.5. CERT-BUND marks the issues remotely exploitable and records that fixes exist.

The affected set

The named projects are Webform, Project Browser, Editoria11y Accessibility Checker, Commerce Decoupled Checkout, Webform REST, REST & JSON API Authentication, Stop administrator login, Cloud, Mermaid Diagram Field, CookieCuttr, Tawk.to-Live chat application, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content and Diba carousel slider.

Webform, Project Browser and Editoria11y Accessibility Checker each appear with two affected ranges, which is why 16 projects produce 19 ranges.

Mechanism and exploitation conditions

The record shares one impact statement across all 36 identifiers: arbitrary code execution, privilege escalation, security bypass, data tampering and disclosure, and cross-site scripting. The flaw class per module is not stated, so the inventory, not the impact wording, drives the work.

Exposure context

ZoomEye returned 436263 instances for app="Drupal" on 25 September 2026. The count indicates how many Drupal deployments are visible, not how many run an affected module. The identifier query returned nothing.

Remediation and mitigations

Build a row per installed contributed project, record the running version, compare it against the affected range, and update to the fixed release. The per-project Drupal advisories sa-contrib-2026-154 through sa-contrib-2026-191 carry the authoritative version detail.

After updating, confirm the installed version changed; a successful update command is not proof of a successful update.

References

  • CERT-BUND advisory WID-SEC-2026-3554

  • CERT-BUND structured record: 16 projects, 19 affected version ranges

  • Drupal security advisories sa-contrib-2026-154 through sa-contrib-2026-191

  • ZoomEye app="Drupal" exact count 436263, checked 25 September 2026

Top comments (0)