it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Webform - Critical - Remote Code Execution - SA-CONTRIB-2026-175
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Webform - Critical - Remote Code Execution - SA-CONTRIB-2026-175
- Date: Wed, 23 Sep 2026 16:45:25 +0000
- Arc-authentication-results: i=2; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="h1/h+O3n"; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=ZXuUeUmW; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="h1/h+O3n"; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=ZXuUeUmW; arc=none smtp.remote-ip=54.240.27.116
- Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org DD29E61292
- Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org 6C7486067B
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790184760; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=VBKRqySIYOpvyXFtnvvYYY4O9kG/qHAoCzPylzs/SEA=; b=tduQKIrGdGzEB4VLkpSRZt2ShxLYiNTmfJH8rBOn2aBSzZI7wysGzyK1HPKByuQJbUsV pxMMzBVh3Vl9cDfLFF6RaRlJcnZu7+x3Hr0FN7NtoUNnVv08Fj2/Iv0a7eak3tCopwwee bO4AKMrcX/nS9j8pwv0AAZHZOIXVRg5qnrHWj8xRW0GTnN3ypIvj06Mgf0+1f+x7vJA0v P9SpbWzlv6/IX+umeKJM1Rwpucq1jWELedwq9n0mBoOzrJirmkd0pOj3r3rBbMwJu+Iub ydAzsb6bnfLqyAcfXKBadz7CM6frnS7ufECvI0foufYhvYoFHtMTvCUfjzp/fzCr1qw==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790181927; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=WPCAzMtTw7LBPnm1rUHgUW80Qpar2Te4PfxpPyvByZU=; b=DQlNGSMfHl4iujkCC4J0wqkA1dctpYayfUAn0s+OU+wGe02dwCaMo6rmOHqu/10jWnB3 kpre9wH/QY7P4Mti4eWbD6HSruAC7wqvoVRn/puq0rU4Yl5glSIzNtby6aI66IjVTkTne 85pVHa0eOJF3o8nDsVYV3HnNW4nssFQ9Lea/OL/NZNLLXNbT6Dq1PlC/R9xyUQQqPtRvh h8GskxXQoltPULPLUu2+xJ/CQV6qDHzXDvrRjoKcHKH2HsiY9bFQYjnbOkmqRe9Um2qjw L19epsoJaURLAbkcDp4LBm8RH/VlrfrGcWOzAPbd9/yhOO8I7nZ4fLkTfaboUoVhFOw==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790184760; b=NSCEgEevv10std/QoCCslarO8mN5vUyJoUEPxteCvGWJ0QRDap/grPE7pQT8DNfqbpJ7 9XyHJBbwcFhzTUt+lP09PFzQ+Yuts/wQXQymmh061q5s8+41TWFU+GfnfZrrZUEPIgx3G 6gBvtmz9kV0H+gYb9wqtVH0oCbH45VHTiTZHwbNrDf3ECOvH6j74JvQO6tu2A0GeCNH4k YKuAiJWeLBjs9e31nPKiuQ4DitsxNcl685gBdUZvTaFLPxL9lpoW/HGP96ZiXv/P7Imli BKVbh1Dzun5LnrCb3ooj3ttHbBQbZrbbhG6Dy5vSV85UglQEM46fZDhL+lTKPw3SOpQ==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790181927; b=geFo3V2rju6UqnnZ2nmp1mv/pJ/xYn6tbyORi+xtoPI4QPSARqQ85iBQy6TsGAYBFQdu YSSxjc/IU7g8E/dI8hPUSXTkUKVLI55j7MIWxm7opLEll40O1P2hy9ZQIFg6aQAhumTgH E5AwqDlHjdzwIYruUTmlVT/gGaDR/c0yFYSErEvXIn7C+vTRcB25Tx7xRv30r5nzpuWpy BQjxc96Kz5mVkWHOSCFYcOAR7lHxv4n75sZ3WTBQDKIP3jetPk6qZ6T4mLt1mJXA35l89 JKi7/qZCKuvQklS5TK6pvR9P466rqbZQFKmLWFSbhlwXqqBbPJuPXMgrEEpD2isOBNg==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/GWAYPJ5FN7ECW3YXTJNU4DKEKD5FIIAZ/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=LhmJX+En; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="h1/h+O3n"; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=ZXuUeUmW; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.136 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-175
Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Critical* 18 ∕ 25
AC:Basic/A:None/CI:All/II:All/E:Theoretical/TD:Uncommon [2]
Vulnerability: Remote Code Execution
Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96355
Description:
The Webform module allows site builders to create forms, collect submissions,
and render submitted values in configurable formats.
Webform does not sufficiently exclude certain format templates from token
replacement. This can allow an attacker to submit data that is evaluated as
template code when a submission is rendered. Depending on the site
configuration and enabled modules, this may lead to information disclosure,
stored cross-site scripting, or remote code execution.
This vulnerability is mitigated by the fact that an affected webform must be
configured with a custom multiple-value item format that includes
submission-value tokens. Some impacts may also depend on additional enabled
modules or site-specific configuration.
Solution:
Install the latest version:
* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].
Reported By:
* Michael Maturi (michaelmaturi) [5]
Fixed By:
* Jacob Rockowitz (jrockowitz) [6]
* Liam Morland (liam morland) [7]
Coordinated By:
* Swan Kalata (akalata) [8] of the Drupal Security Team
* Bram Driesen (bramdriesen) [9] of the Drupal Security Team
* Greg Knaddison (greggles) [10] of the Drupal Security Team
* Jess (xjm) [11] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [12]
[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/michaelmaturi
[6] https://www.drupal.org/u/jrockowitz
[7] https://www.drupal.org/u/liam-morland
[8] https://www.drupal.org/u/akalata
[9] https://www.drupal.org/u/bramdriesen
[10] https://www.drupal.org/u/greggles
[11] https://www.drupal.org/u/xjm
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3595570
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Webform - Critical - Remote Code Execution - SA-CONTRIB-2026-175, security-news, 23.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.