Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-167

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-167


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-167
  • Date: Wed, 23 Sep 2026 16:45:53 +0000
  • Arc-authentication-results: i=2; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Ip0ccijH; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=tOB5fsIr; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Ip0ccijH; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=tOB5fsIr; arc=none smtp.remote-ip=54.240.27.115
  • Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 52B8940A33
  • Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 7BEBE4077C
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790184995; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=/AJKe9hYBqzL1N2AYK/jYP0qBslNmOjuV2E/NypGHTQ=; b=Ujk+jy5lAEcp4BqmfnASv2YkHVggSknUEh2D0KYRJFKr2zn7p5dRqfRcniivk0Cwl8Qg Vko7DkBf8OU8M0uJeEn5pNhEuNCM9pTbyoDITsAkVAcXZlH29TPstx8VlzwTkfPTnAk3f 195PsvYb5DcyMbVtE8M5z0w7efn/UA2CSwoM4fTHueDa7cH4qN9EPmejTl1JivuCdyg66 mih77OCQZfCZ1Y0Iq9RUOfQf0dYaTzY+bL+xZIHodgRMN9/Wdq/yeXAIZ2sl63uYkKDCc 6fabQ2cuz81mp06jsPIrGmeNtnqc0Q+YkTJBwfPg0uVaH6wbkLZ29aTkn1qxum/tICQ==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790181953; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=fvjPzJZQVS0POPIOVYx44xXZ57Nquc6Xg5k4XQqrlgc=; b=MUZ1TjpopUEmITPqGuywPm4zGLWa5/a+po2hEAldJQSZuWcy25oqDJ9tjtZZ4+JDj+Kh RcixMb8A2PPcL1aZn6n3k5zKVPHOPCl7YiRDGimWidpoK8DL6Xc20egzjBy19KUoHiXXn Kn46FTunMjixR+SsISsL4KF1ylsHWd7vwxiaEweN5bUIoIIR9KlGNApBVqgpYnchG2X1o dCh7T0ZDdF5x4ncY4zz6nr/fijemRH7QWF0nCJN995E32saadymajM5wHl8pP0owSLFbv +3STHaNO76pYoGTHtDZ8hAjYOGI71V2mcFMaFtDs5ylG4xuawD0Szqlgb58HbGl4fxQ==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790184995; b=N5uMF5nw8q3nDUpzBcuKMpxnZcgvkiHVn2v8srTh0dlXp0bW9SZ4j/PUmry7kflMDhAH QeRe1xCFicHZp7b0kbcCPXS5oVMKYfwe4ZyYVPRiCUUAvybUlfmi72Fhrb4lximfmXgOh UhaZ1olX1S6SMSDDCHtlXpV43D1IWwOKpAkcKwBrL5L/6Kxq4wjaebTWFiHNeAVXCcEgH XBMChJ5y6vWffIGOK+khbiIxyWD0+3rB4F/tsTftfU+4YS3RPnggXq3C560Lq2cdnYQNA TE/gI20tJNBOJ4nGU7pWWt3FBWPon7vOO/tOUyBY7dBlYfeyZbfc7oBTa23ftseNKsQ==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790181953; b=lB+2550Gng4rAvR9Vz0j/JFHeLUebIg6iMODwlBnGIQ6AFIDDfL6e5sW9nwh/hC1dXqe BE28gFnRr3lyELoWsJUyqb3ittwY1+opM++dA5zZxkezie8yAdl7GsDCgb5daa7HayeKN oUa7a5aeZ324O0oGPbVstaJhKLGk6b+UlmzSqi/u08uFKLvqG5BH0FkWKyXJuvdFZMvbt AU0GNn9nzWOGLUmOP8lW4cBnsa+8JE2qJq/ePGCJAA41wPYUF8f3nzaG8Q5Cq0izIeDqw FSHjmc6P0iAo6YON7Sv1JQNBslvxczHZjzW/Th4A77WDvITpR6ybkqUta3Mi/hokf2g==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/FTKRBPLCCOH5H6X5EKJOUIVUA3X2V57C/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=CnKaTE1p; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Ip0ccijH; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=tOB5fsIr; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-167

Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Access bypass

Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96372
Description: 
The Webform module enables site builders to create forms and collect
submissions.

The module does not sufficiently restrict access to configure Remote HTTP
Operations handlers. This vulnerability could allow a user with permission to
edit a webform to configure a remote HTTP operation.

The update adds the /Administer webform remote post URLs/ permission. Review
this permission and ensure it is granted only to trusted roles.

The vulnerability is mitigated by the fact that an attacker must have a role
with permission to edit a webform.

Solution: 
Install the latest version:

* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.11 [4].

Review the new permission /Administer webform remote post URLs/ and ensure it
is only granted to trusted roles.

Reported By: 
* Pierre Rudloff (prudloff) [5] of the Drupal Security Team
* Wesley Giles (seraphdev) [6]

Fixed By: 
* Dan Chadwick (danchadwick) [7]
* Jacob Rockowitz (jrockowitz) [8]
* Liam Morland (liam morland) [9]

Coordinated By: 
* Swan Kalata (akalata) [10] of the Drupal Security Team
* Bram Driesen (bramdriesen) [11] of the Drupal Security Team
* Greg Knaddison (greggles) [12] of the Drupal Security Team
* Lee Rowlands (larowlan) [13] of the Drupal Security Team
* Juraj Nemec (poker10) [14] of the Drupal Security Team
* Pierre Rudloff (prudloff) [15] of the Drupal Security Team
* Jess (xjm) [16] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [17]

[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.11
[5] https://www.drupal.org/u/prudloff
[6] https://www.drupal.org/u/seraphdev
[7] https://www.drupal.org/u/danchadwick
[8] https://www.drupal.org/u/jrockowitz
[9] https://www.drupal.org/u/liam-morland
[10] https://www.drupal.org/u/akalata
[11] https://www.drupal.org/u/bramdriesen
[12] https://www.drupal.org/u/greggles
[13] https://www.drupal.org/u/larowlan
[14] https://www.drupal.org/u/poker10
[15] https://www.drupal.org/u/prudloff
[16] https://www.drupal.org/u/xjm
[17] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3613031

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-167, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang