{"id":"DRUPAL-CONTRIB-2026-166","details":"The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.\n\nThe module does not sufficiently restrict access to raw webform source editing when the Webform UI module is not enabled. This could allow a user with webform creation or editing permissions to enter source configuration that is rendered unsafely.\n\nThis vulnerability is mitigated by the fact that an attacker must have permission to create or edit webforms.","aliases":["CVE-2026-96371"],"modified":"2026-09-23T17:40:56.639127Z","published":"2026-09-23T16:17:47Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-166"}],"affected":[{"package":{"name":"drupal/webform","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/webform?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.12"}],"database_specific":{"constraint":"\u003c6.2.12"}},{"type":"ECOSYSTEM","events":[{"introduced":"6.3.0"},{"fixed":"6.3.1"}],"database_specific":{"constraint":"\u003e=6.3.0 \u003c6.3.1"}}],"database_specific":{"affected_versions":"\u003c6.2.12 || \u003e=6.3.0 \u003c6.3.1","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/webform/DRUPAL-CONTRIB-2026-166.json"}}],"schema_version":"1.9.0","credits":[{"name":"Pierre Rudloff (prudloff)","contact":["https://www.drupal.org/u/prudloff"]}]}