Project:
Project machine name:
webform_restDate:
2026-September-23
Vulnerability:
Access bypass
Affected versions:
<4.2.1
CVE IDs:
CVE-2026-96391
Description:
This module enables you to retrieve and submit webforms via REST.
The module doesn't sufficiently check permission to webform and webform submission entities when retrieving webform elements or fields.
Solution:
Install the latest version:
- Upgrade to Webform REST 4.2.1. The 4.1.x branch is no longer supported.
Reported By:
Coordinated By:
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Mohit Aghera (mohit_aghera) provisional member of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team