it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087
- Date: Wed, 22 Jul 2026 18:00:54 +0000
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/2VOU7XMOUM3W7X3O2WLQMU2BZRKIANWG/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=Pg+102f0; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=lnmb5BCc; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=szatgu01; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp4.osuosl.org 61DD54EC7E
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp4.osuosl.org D878B40589
- Dmarc-filter: OpenDMARC Filter v1.4.2 smtp4.osuosl.org D878B40589
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-087
Project: Webform REST [1]
Date: 2026-July-22
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Access bypass
Affected versions: <4.0.3
CVE IDs: CVE-2026-16644
Description:
This module enables you to retrieve and submit webform submissions via REST
endpoints.
The module doesn't sufficiently check the parent webform's permissions for
creating, viewing and updating permissions.
This vulnerability is mitigated by the fact that an attacker must already
have permissions to use the rest resource.
This advisory only affects already-unsupported versions 4.0.3 and earlier.
Solution:
Install the latest version:
* If you use the Webform Rest module for Drupal 8.x, upgrade to Webform Rest
4.1.0 [3]
* Version 4.2.0 already has the fix included so no action needed if you use
that version
Reported By:
* Giuseppe (giuseppe87) [4]
Fixed By:
* Dan Chadwick (danchadwick) [5]
* Giuseppe (giuseppe87) [6]
* Jacob Rockowitz (jrockowitz) [7]
* Liam Morland (liam morland) [8]
* Nelson Alves (nsalves) [9]
Coordinated By:
* Anna Kalata (akalata) [10] of the Drupal Security Team
* cilefen (cilefen) [11] of the Drupal Security Team
* Greg Knaddison (greggles) [12] of the Drupal Security Team
* Michael Hess (mlhess) [13] of the Drupal Security Team
* Juraj Nemec (poker10) [14] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [15]
[1] https://www.drupal.org/project/webform_rest
[2] https://www.drupal.org/security-team/risk-levels
[3] project/webform_rest/releases/4.1.0
[4] https://www.drupal.org/u/giuseppe87
[5] https://www.drupal.org/u/danchadwick
[6] https://www.drupal.org/u/giuseppe87
[7] https://www.drupal.org/u/jrockowitz
[8] https://www.drupal.org/u/liam-morland
[9] https://www.drupal.org/u/nsalves
[10] https://www.drupal.org/u/akalata
[11] https://www.drupal.org/u/cilefen
[12] https://www.drupal.org/u/greggles
[13] https://www.drupal.org/u/mlhess
[14] https://www.drupal.org/u/poker10
[15] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3611659
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087, security-news, 22.07.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.