Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-166

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-166


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-166
  • Date: Wed, 23 Sep 2026 16:46:03 +0000
  • Arc-authentication-results: i=2; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=F1ds0vgR; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=JiGMMFX0; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=F1ds0vgR; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=JiGMMFX0; arc=none smtp.remote-ip=54.240.27.115
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org 015846107E
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org A94D8605E5
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790185066; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=D/gn05m/1IbC55OE7ZCzXv6rh2DGH/hbzlm4pRH1ArA=; b=GhvcztjZpSLRjCvHzCMsJyuXQZB2tsa2RiCrGX9XhdYxzll+ilAOT41sarAwxQFejm94 AnCvYzON6ymMIQt3hOfXr7LWttHHVtlXEJrddL06IOu+OBa3nwBW3E4LEPGeSYSgcN8H6 jGEgtb1G/l6dnonxweqfSp0FjIh6/jhgpYeZ1tP0PtkmIdXUWd7CD0SMurd/xzbfQHX1A JV0nIGIqdY6NQVnY1zCkQkvEIxiC/Mz23UuglNig7ApgwKL10qO2mrKAmduC/zf/AiZ2E pObc4SIDXAm8Nh8Aqb0KWWb1W4s482iDtZPV63LxUV6XisM0ysGXPIYjVaq2bdh21VA==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790181965; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=oB9PhlBOTEluIHfo7A618g9jlXEh/6MvtR32QOGJOD4=; b=auGi6PeTntSlbitWBTKdMshQTVeZZ9ujMGSYMCPgmQxtN3tnQS8lDJT6hneSEtXoPKzc 5wh/JwtOg3m5N0yG+rIbGLEepGtKNThe4324vaSvnczz9XqxztdCMkiOrWEyeAZKgUavU 7XqT/QcfoWGcFXHPdqRHI+vizepdwH2+caKPRd53Ph3L5E8b/KsEeTsxmNwc75PG3GDgC 3CzP4Izh/eAvIV6aGBjsrNVrCLeAMpR25wzGjTIq2jCi1KKEJAXyps76Act+dt17/d2h6 xt+2N9Z0JW84lOjg64/ycrQtKUAH5CmKJM9GIlRirPFIQRtiiLoOpM35XFCHnUlMJ5A==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790185066; b=HVzW1lu/yQzQm+9aMwv5bew+5DOw0eb3j+UwY2UNTWHn8iR5SjlDpOG9RpzMnjlgH9Kk cxnwjCnFMpjF1oE8/mzX8Am2205GnlglbLd9EfZb3uQ68Ou7BfQx+OoVn1ytbicgXA8NS A0MiNIb9Y3gU07L1LQW5VXxHje9xnx0KmGZhVeBNJUOLBRnWqfZHEL78xfTPtN6SZ2RWX lLHeqmNlaiwZy7R+bpKfr6ahbUcq8vtIgwuk5F0filyBWG/hgYCjR195KZobOVer+A+Sf 8T5+l7Tt+nBjbgkR7bJpVwslYy6x3r8IDmmZq3658UZyh3zZRy/F+GqRWfhfD6boGAw==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790181965; b=pO4zN7a8PjizoDhYF5S1qAQfP/c5JE3y6TTdg9Bw6djlK1UAKgxpo+2aJihXOgQKlXeZ tQL04u8H4jAejbOMbXg0aKgb+SWb5o7+0cb4Q9w4IDnAZPOjQt1RrWzztIEhsjb9rt8zR U+3CHFumoLwwJSm0g0Jmnbo2fSblUi5tdQhClIIgKsKwggwFf16sLsUpQ3knYKn92MRdd 9dDJdyB1cTB3NSTjEhAyBblo4vq+jwPP1R8dFLoeQ+NvQ8Y3q37iN7rDg8zEbsqPC7Slx nx3XGsJ8iH8CV+jr+UkWYEBcqmnc/tZbZtv8RCnfH4LBPgWq2mFmdsCA/f1uhCfBM0Q==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/SUCUQQFPCJSTBMQBZX747DY52R7N2RU6/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=M9GJiSeA; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=F1ds0vgR; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=JiGMMFX0; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::136 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-166

Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Cross-site scripting

Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96371
Description: 
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data.

The module does not sufficiently restrict access to raw webform source
editing when the Webform UI module is not enabled. This could allow a user
with webform creation or editing permissions to enter source configuration
that is rendered unsafely.

This vulnerability is mitigated by the fact that an attacker must have
permission to create or edit webforms.

Solution: 
Install the latest version.

* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].

Reported By: 
* Pierre Rudloff (prudloff) [5] of the Drupal Security Team

Fixed By: 
* Dan Chadwick (danchadwick) [6]
* Jacob Rockowitz (jrockowitz) [7]
* Lee Rowlands (larowlan) [8] of the Drupal Security Team
* Liam Morland (liam morland) [9]
* Juraj Nemec (poker10) [10] of the Drupal Security Team
* Pierre Rudloff (prudloff) [11] of the Drupal Security Team

Coordinated By: 
* Swan Kalata (akalata) [12] of the Drupal Security Team
* Bram Driesen (bramdriesen) [13] of the Drupal Security Team
* cilefen (cilefen) [14] of the Drupal Security Team
* Damien McKenna (damienmckenna) [15] of the Drupal Security Team
* Greg Knaddison (greggles) [16] of the Drupal Security Team
* Jess (xjm) [17] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [18]

[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/prudloff
[6] https://www.drupal.org/u/danchadwick
[7] https://www.drupal.org/u/jrockowitz
[8] https://www.drupal.org/u/larowlan
[9] https://www.drupal.org/u/liam-morland
[10] https://www.drupal.org/u/poker10
[11] https://www.drupal.org/u/prudloff
[12] https://www.drupal.org/u/akalata
[13] https://www.drupal.org/u/bramdriesen
[14] https://www.drupal.org/u/cilefen
[15] https://www.drupal.org/u/damienmckenna
[16] https://www.drupal.org/u/greggles
[17] https://www.drupal.org/u/xjm
[18] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3611234

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-166, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang