Project: 
Project machine name: 
webform_rest
Date: 
2026-September-23
Vulnerability: 
Access bypass
Affected versions: 
<4.2.1
CVE IDs: 
CVE-2026-96391
Description: 

This module enables you to retrieve and submit webforms via REST.

The module doesn't sufficiently check permission to webform and webform submission entities when retrieving webform elements or fields.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: