it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-168
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-168
- Date: Wed, 23 Sep 2026 16:44:41 +0000
- Arc-authentication-results: i=2; smtp1.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=E0G0rIr+; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=MKg7OJEY; arc=none smtp.remote-ip=54.240.27.34
- Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 4248881469
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 3F301407FF
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790184680; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=At57xJdnRdIIoqcv4x3v78HA1YyMl2Eb5BFkCJS5XZg=; b=ZLComyuuKsIUFshGX9S7GeLeC+bG0NmhoUqKqRH2LRhBrpGsXjEmT58Ae3ZxbEAdB+LT nkQKMkg8BEGyXIxh88IZ0QouigHzsONit7RBuEUrqR+1umJhtFVfX/r/lgZcRzj/nf4tl cAvzNdRi+MjvCX976QAHypyzfATG00yT5oPppL38x46Mj1rWu1O+yHexPazEH7wcPzekZ Apk1y/Cg37bO6UV9hgpJvHEUQM60kmwGHDR01Wm4jAI++nvhZUqtj5BtWvk4W/kwULSHi AJY4P1WJPM1dWu72f0z8SK0tz4T5eomW31iXX2TOXLTf0w2/Hsze+UhoxGwG8uy5BLw==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790181882; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=btv9gRlLKJLoAdAgbckuogOvNCoPcAYvkZKbqQQttaM=; b=exDhOLZnfFTjc83AVdymQTveMK/mU4hkGPanS2S78BbYD6chCyvxpkpRSfnHPiB1VBah 4Y6hX8kmrrflPmm5Qcp8IpLALK6THJPQKTQvvtIRnL0Ds1XG+llNGRaNT7iQXiNQnmWbV cjc8ZzRdJzmhIOm6S1Qx8qjDoK0PuLfP8DzBMRUXNwNN1JkPQmUTjeg5Q9eT0LXgnwNtT edpQ+pjHKZlY9wbCgUr514XTGb3M5RXGpSXES0XK2tTu7ZTMbNnvsS2MqzP7FgSXY1JFK Uqtw50K2gW+d7+638T/laNmggAu9+epZP80CtKc7mc6H9a0ZMlQuKbdjrvRbjeLHEIA==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790184680; b=NLhxVzZcfMbIU9vGM1Wkmoq6ChLHQUYFzZO3J+U8OokK0mETyVS3eUTYiH62ik0G2eu/ e0kZbBjfKb0+IRaKxR5HP0UrDhc+R3IznrVcZfYvoK7+AvLfBPw8sYFnHckSFYXhX/icE wFgGLFY+MXStPqYW2+5XrB9vQxUMZ53iWwCXwDRBoJ+vogkEV84TE/bPmwazqDbX93UkL b2hsSsuIDovpkf+FBAnWl3kDiFk7UJ+Uii/GdHQ10y75I8133tLxxZ+0JVoEcClCQczH8 ntjuwLtf61cw7xJlOTKbolPqRftlW5IqfTtqJLjb4A8O0NnCspq8NuvSvhaPV9r285A==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790181882; b=dGCUq5SYfjgm7bCTS//QRB9g4kJyajQyhK9VLx2s+Hcd8giyThVcnGSPVPhpTxNTpGgJ aNEh1VzgUWLvsgPaD+da33u+EWZ0fLeC3s37WFaRhPRFusqEryf0Fmsdabu46fYqAsPfx CshVT4z2/27NK+gBiYHNf4Qn76CnkWj1E6aix2MCt9ededuKc97YgpuQCPcjt/WYRd7pP lZTCfxSBMZZOd5hOL649Twd1XVWWkV8ThsgnqgckTiE82grTorybVDQz0OCutBgWYifoi eKjOCVRBSfICztQbE5lRXl76o+X8RXo12b8afOdzx91wAtT0+KY37wf+OMK5lRQKLOQ==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/FIWQTFWO3IX4LDZPCNDPNYPDNC2PE6GH/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=Z27j9azY; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=E0G0rIr+; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=MKg7OJEY; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-168
Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 11 ∕ 25
AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Access bypass
Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96373
Description:
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data.
The module does not sufficiently validate requested filenames when serving
generated submission exports. Under certain configurations, a user with
permission to view submission results for one webform may be able to access
or remove files from the configured export temporary directory that were not
generated for that webform.
This vulnerability is mitigated by the fact that an attacker must have access
to view submission results for a webform and must know or be able to
determine a target filename.
Solution:
Install the latest version:
* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].
Reported By:
* Marcus Johansson (marcus_johansson) [5]
Fixed By:
* Jacob Rockowitz (jrockowitz) [6]
Coordinated By:
* Swan Kalata (akalata) [7] of the Drupal Security Team
* Bram Driesen (bramdriesen) [8] of the Drupal Security Team
* Greg Knaddison (greggles) [9] of the Drupal Security Team
* Pierre Rudloff (prudloff) [10] of the Drupal Security Team
* Jess (xjm) [11] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [12]
[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/marcus_johansson
[6] https://www.drupal.org/u/jrockowitz
[7] https://www.drupal.org/u/akalata
[8] https://www.drupal.org/u/bramdriesen
[9] https://www.drupal.org/u/greggles
[10] https://www.drupal.org/u/prudloff
[11] https://www.drupal.org/u/xjm
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3623421
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-168, security-news, 23.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.