it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-174
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-174
- Date: Wed, 23 Sep 2026 16:45:34 +0000
- Arc-authentication-results: i=2; smtp1.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=X2WzPMWB; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=sj8m3FjF; arc=none smtp.remote-ip=54.240.27.35
- Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 63F0D81355
- Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org BCD7F40390
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790184844; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=cKIsXOJzyKMIpq6K1C5s0hDDpRfVqfjlHAlb8WJTla4=; b=GzQKgT1ELThp0sr+pV8IDPADl50fejx+9xr4JitTgzsRhX3adqmHmyKGbyWUwESBINsh +4ADMVG+hWU4Ha53cPx2Bvegv1X4WdfbpbhgAt+0MSaGfkRr6JX/etVOdsXQjtxL8VAVE NpAPSCsciYV2ZiOQLUeaXFJ/WDtvg8SaphruTEmwYTdSEGZuIuFNjU7O/XzW4bMZ3dbgu MZIL8Cro7kQjsXxTqyHhkIoVY+pgcQA8E+1QyauV5PhASka094oVjQ3djlZpeVSo91IW8 m4ugh/lcaa6cBlHT3i24DWXAUdWRjgHRrvVNuGrrw5KgELR/uKB3OZcjyYMOAZcCqiw==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790181935; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=+iIgKyvAlstw5UtsLNdinA1RNrfXPhnsIaZgCGv+yWw=; b=djJ0A0GGIZ5iNcnfRFFGJ2wLYisRwak4yO9H5GTpiUDaB2N60kZt+9jwmBpf+ncAYsns ORBB7g8QhpIGkTlF4s3Sklm1hXRdKNwVTcizXndWuNPM7OY2My5loEvMmWt8Ib6MR7Jdk /H7jzlcNMOa3xL9c5I6Cjxr94cKmKTVc69Wr550Uj2cwRmGmdxWfehH4dtyuCzK0waOhU nJBufDu34aTINn9H1RtZ1MnaWFJ2eNNpo9q58oYdQG4CfFkAQMHxbEjGQsUa8pzskUeEB ZOStHBFJ/s7/NVvOxNfL3Kd+YDkWPNAzeo/iy9ZMF1HTQpsFWRhJiTd/L+u8wlnE5JQ==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790184844; b=RQ95zhdLyUJ18KU6mLhmEYTedlFAHnHmOuTWgRJTw4OSvJqtG71FZ/or1aRqdcQZQKGu kXFfvHujnGfwKlE0E7hM2YGbIxFxwPi042MyT4DORe/xi5zi5J8ERnZsRGbTFla88oPgX uMOhokT4xFbz1nMXci6qzfv24IqAkJlGjgyw2/9baEs9l9+9T3LtOMykno1lOIuh1sTKj 9B5hBStgz+PWxvRookoZv3M3vJiHNoRQC41QrzkHZLfmGH/wtL0Ut37cyLisDF8a24sxJ 9lrd3D4ED1bEd5xHBrkBO4vsqNSFuHf+JNbje7xJuTrNMi9y6YD0r7BIgDODmkxiXxQ==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790181935; b=SIBkYz560OjMs/GODeUNW2+L+wypko994BAKlQbgo0QvyEYqKhu+Yxf+BQLzFE47VPJf QB2vLYgrGzd5sgNwDzGdcqFpuXBB8tZaxz+hBlHoxQOWsd+AdMNvliN5FpEaBi07StMTD 9K4FEzN/p7wnjzKyRvlGPbi3fRJfOAnvxk9zcIyOImQg7RhZ7H8a3rQ+vn+hvbjl32NkL jNSPMcOYfFfdGZoHUl2kNXO4tn1aNd5kQ4BOvTBKGzzlr/+LR2fearziphaBHX8v4xqtO qThmq4wokY2d5dy0PySniPa2W0K+Vxket/eTvs9t9uLo6bZDo4rzy5qYIIZ4y97OspA==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/V4OATOHJQJ23YXVFTGQ2FS3MXQ46GDL7/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b="AJ9/GyQ5"; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=X2WzPMWB; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=sj8m3FjF; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-174
Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 11 ∕ 25
AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon [2]
Vulnerability: Access bypass
Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96356
Description:
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data.
Webform did not sufficiently guard user-specific access rules against a
malformed saved configuration. Under certain site-specific conditions, an
access rule intended to grant submission access only to selected user
accounts could also grant access to anonymous users.
This vulnerability is mitigated by the fact that the bypass depends on
malformed saved access-rule configuration.
Solution:
Install the latest version:
* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].
Reported By:
* Adam Bramley (acbramley) [5]
* enyug [6]
Fixed By:
* Jacob Rockowitz (jrockowitz) [7]
* Liam Morland (liam morland) [8]
Coordinated By:
* Swan Kalata (akalata) [9] of the Drupal Security Team
* Bram Driesen (bramdriesen) [10] of the Drupal Security Team
* cilefen (cilefen) [11] of the Drupal Security Team
* Greg Knaddison (greggles) [12] of the Drupal Security Team
* Lee Rowlands (larowlan) [13] of the Drupal Security Team
* Juraj Nemec (poker10) [14] of the Drupal Security Team
* Jess (xjm) [15] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [16]
[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/acbramley
[6] https://www.drupal.org/u/enyug
[7] https://www.drupal.org/u/jrockowitz
[8] https://www.drupal.org/u/liam-morland
[9] https://www.drupal.org/u/akalata
[10] https://www.drupal.org/u/bramdriesen
[11] https://www.drupal.org/u/cilefen
[12] https://www.drupal.org/u/greggles
[13] https://www.drupal.org/u/larowlan
[14] https://www.drupal.org/u/poker10
[15] https://www.drupal.org/u/xjm
[16] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3597025
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-174, security-news, 23.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.