Module inventory hygiene in the light of CVE-2026-96360
Vulnerability overview
CVE-2026-96360 appeared in Drupal's contributed-project release of 2026-September-23 as SA-CONTRIB-2026-154, a Moderately critical cross-site scripting flaw in the Webform module with a risk score of 11 out of 25 and the vector AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Uncommon.
The case for knowing what is installed
Webform is widely deployed because it solves a common problem. That is also why an advisory against it produces a large affected population overnight. Sites that can produce an accurate module list, with versions and an owner per module, can answer the question in minutes. Sites that cannot end up patching on the basis of memory and hope.
Mechanism and exploitation conditions
The flaw is in the JavaScript announcement behaviour that reports dynamic form updates to assistive technologies. Sanitisation of the announcement text is insufficient, so crafted content can be parsed as page markup. Exploitation requires administrative permissions on the affected site and the target distribution is uncommon.
Impact
Script execution occurs in the session of a user who interacts with the affected form. Drupal rates confidentiality and integrity effects as Some and leaves availability unaffected. With an administrative victim, control over content and configuration becomes possible.
Affected products and scope
The affected project is the Webform contributed module for Drupal, machine name webform. The same release round carried advisories against other contributed projects, including a critical remote code execution issue. Fixed version boundaries come from each individual advisory.
Building an inventory that helps
Record the project machine name and version for every contributed module, the reason it is installed, and who owns its updates. Review the list on a schedule instead of at incident time. Remove modules that no longer serve a purpose, because an unused module cannot generate an advisory you have to triage. Where the tooling allows it, subscribe to the Drupal security advisory feed and map advisories to installed machine names automatically.
Remediation and mitigations
Apply the September 2026 update to Webform and to the other contributed modules that received advisories in the same round. Verify the effective versions, clear caches, and reduce administrative accounts so that the precondition behind this flaw is less common. Then close the loop by updating the inventory with what actually changed.
Exposure context
On 2026-09-26 ZoomEye returned 0 results for vul.cve="CVE-2026-96360" and 436368 for app="Drupal". The product count describes visible Drupal installations in general and does not identify which of them run the affected module.
References
Drupal security advisories, SA-CONTRIB-2026-154, https://www.drupal.org/security. CERT-Bund advisory WID-SEC-2026-3554, https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3554.
Top comments (0)