DEV Community

StarkMan
StarkMan

Posted on

Reading CVE-2026-96364 in the September 2026 Drupal contributed-module batch

Reading CVE-2026-96364 in the September 2026 Drupal contributed-module batch

Overview

CVE-2026-96364 is one of 36 CVE identifiers carried by CERT-BUND advisory WID-SEC-2026-3554, titled Drupal Erweiterungen: Mehrere Schwachstellen, first published on 23 September 2026. That advisory is rated high in the German risk scheme. Its machine-readable record sets a remotely exploitable flag to true and cites a CVSS version 3.1 base score of 98 with a temporal score of 85.

The identifier is a batch entry. Thirty-six CVEs under one title means the batch is the unit that needs triage. A single identifier does not describe the whole problem, and reading it that way leads to bad decisions in both directions.

What the source establishes

The advisory states that an attacker can exploit multiple vulnerabilities in Drupal to run arbitrary code, gain extended privileges, bypass security measures, manipulate and disclose data, and carry out cross-site scripting attacks. It lists 36 CVE identifiers and 19 vulnerable and fixed version references covering 16 contributed Drupal projects, among them Webform, Cloud, Project Browser, Commerce Decoupled Checkout, Mermaid Diagram Field, CookieCuttr, REST and JSON API Authentication, Stop administrator login, the Tawk.to live chat application, Editoria11y Accessibility Checker, Webform REST, AI CKEditor, Combined image style, CSS Usage Analyzer, Smart Content and Diba carousel slider.

It also points to 36 Drupal Security Advisories, sa-contrib-2026-154 through sa-contrib-2026-191, all dated 23 September 2026. Those per-project records state the vulnerability class and the affected version range for a specific module.

What the source does not establish

The machine-readable record does not publish a one-to-one mapping from each CVE identifier to each product reference. The version table describes project ranges in the aggregate, and it does not say that CVE-2026-96364 is the identifier for Webform, or for any other named project. The advisory also publishes no proof of concept, payload or reproduction sequence.

That gap matters for planning. Anyone who needs to know which code path in which module carries CVE-2026-96364 has to read the corresponding sa-contrib record. Anyone who needs to know whether a specific site is in scope has to read that site's installed module versions.

Affected products and versions

The affected set is contributed modules, not Drupal core. The version references in the batch include ranges such as Webform below 6.2.12 and Webform below 6.3.1, with fixed releases 6.2.12 and 6.3.1; Cloud below 7.0.1 with fix 7.0.1; Project Browser below 2.0.3 and below 2.1.5 with fixes 2.0.3 and 2.1.5; Commerce Decoupled Checkout below 1.8.0 with fix 1.8.0; Mermaid Diagram Field below 1.0.9 with fix 1.0.9; CookieCuttr below 2.0.3 with fix 2.0.3; REST and JSON API Authentication below 3.2.0 with fix 3.2.0; Stop administrator login below 1.6 with fix 1.6; Tawk.to live chat below 3.0.4 with fix 3.0.4; Editoria11y Accessibility Checker below 2.2.23 and below 3.0.9 with those fixes; Webform REST below 4.2.1 with fix 4.2.1; AI CKEditor below 1.4.3 with fix 1.4.3; Combined image style below 1.0.7 with fix 1.0.7; CSS Usage Analyzer below 1.0.2 with fix 1.0.2; Smart Content below 3.2.1 with fix 3.2.1; and Diba carousel slider below 3.0.2 with fix 3.0.2.

Because the list is per project, a site is in scope for the batch when it runs any affected project on an affected branch. The batch is not a core update.

Impact

The stated outcomes are remote code execution, privilege escalation, security bypass, data manipulation and disclosure, and cross-site scripting. These are different operational problems. Code execution on the web tier is a full compromise. A reflected cross-site scripting issue may be contained by browser behaviour and a content security policy. Treating the whole batch as uniformly critical wastes the patch window, and treating it as uniformly moderate leaves the severe entry unpatched for longer than necessary.

Exposure context

A ZoomEye query for app="Drupal" returned 436388 matching assets on 27 September 2026. A query for vul.cve="CVE-2026-96364" returned zero. The first number is a population figure for deployments the platform can fingerprint as Drupal, and it does not separate sites running affected contributed modules from the rest. The second records index coverage for that exact identifier at the time of the query, and it is not a claim that no deployment is affected.

Remediation and mitigations

The practical order is inventory, then branch-aware update, then verification. List installed contributed projects and their versions, compare each against the ranges in the batch advisory, and update to the fixed release for the branch in use. Where a project has no fixed release in use, or where the update cannot be applied in the current window, disable the module if the site can function without it, and restrict access to the affected feature paths in the meantime. Because the advisory covers many projects, schedule the work as several small updates rather than one large change, and record which projects were updated in which window.

References

  • CERT-BUND advisory WID-SEC-2026-3554, Drupal extensions, 23 September 2026
  • Drupal Security Advisories sa-contrib-2026-154 through sa-contrib-2026-191, 23 September 2026
  • Drupal security advisories index
  • NVD CVE API query for CVE-2026-96364, no record published at query time

Top comments (0)