Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087
  • Date: Wed, 22 Jul 2026 18:00:54 +0000
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/2VOU7XMOUM3W7X3O2WLQMU2BZRKIANWG/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=Pg+102f0; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=lnmb5BCc; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=szatgu01; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp4.osuosl.org 61DD54EC7E
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp4.osuosl.org D878B40589
  • Dmarc-filter: OpenDMARC Filter v1.4.2 smtp4.osuosl.org D878B40589
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-087

Project: Webform REST [1]
Date: 2026-July-22
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Access bypass

Affected versions: <4.0.3
CVE IDs: CVE-2026-16644
Description: 
This module enables you to retrieve and submit webform submissions via REST
endpoints.

The module doesn't sufficiently check the parent webform's permissions for
creating, viewing and updating permissions.

This vulnerability is mitigated by the fact that an attacker must already
have permissions to use the rest resource.

This advisory only affects already-unsupported versions 4.0.3 and earlier.

Solution: 
Install the latest version:

* If you use the Webform Rest module for Drupal 8.x, upgrade to Webform Rest
4.1.0 [3]
* Version 4.2.0 already has the fix included so no action needed if you use
that version

Reported By: 
* Giuseppe (giuseppe87) [4]

Fixed By: 
* Dan Chadwick (danchadwick) [5]
* Giuseppe (giuseppe87) [6]
* Jacob Rockowitz (jrockowitz) [7]
* Liam Morland (liam morland) [8]
* Nelson Alves (nsalves) [9]

Coordinated By: 
* Anna Kalata (akalata) [10] of the Drupal Security Team
* cilefen (cilefen) [11] of the Drupal Security Team
* Greg Knaddison (greggles) [12] of the Drupal Security Team
* Michael Hess (mlhess) [13] of the Drupal Security Team
* Juraj Nemec (poker10) [14] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [15]

[1] https://www.drupal.org/project/webform_rest
[2] https://www.drupal.org/security-team/risk-levels
[3] project/webform_rest/releases/4.1.0
[4] https://www.drupal.org/u/giuseppe87
[5] https://www.drupal.org/u/danchadwick
[6] https://www.drupal.org/u/giuseppe87
[7] https://www.drupal.org/u/jrockowitz
[8] https://www.drupal.org/u/liam-morland
[9] https://www.drupal.org/u/nsalves
[10] https://www.drupal.org/u/akalata
[11] https://www.drupal.org/u/cilefen
[12] https://www.drupal.org/u/greggles
[13] https://www.drupal.org/u/mlhess
[14] https://www.drupal.org/u/poker10
[15] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3611659

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087, security-news, 22.07.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang