Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Webform - Less critical - Access bypass - SA-CONTRIB-2026-165

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Webform - Less critical - Access bypass - SA-CONTRIB-2026-165


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Webform - Less critical - Access bypass - SA-CONTRIB-2026-165
  • Date: Wed, 23 Sep 2026 16:46:14 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=X4nY5LiN; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=SM6vSk6l; arc=none smtp.remote-ip=54.240.27.35
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 80908408AC
  • Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org A0164605E5
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790185225; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=gY7s4ynn0rs9J3lE1qWY8Rp80AgAYoMqKGNLrqRzCCE=; b=jkU9y4K8X6ee1fqs/nSUR3gHODchwYVPYcWv3Z6qFoSRPj5/aVGH6NnjxjB+TM7ZvAO/ 2reLjXj+D4uvTqAm3AbYbxaN1VG1geyRDd90Iu6x4RZWcJicWy668UkIcEAC0vMc22mHm 5L95PzNXPU+oe4dr/uJRmH3jA3OGBUaizTH4WPbUaLzHg7c/lVE/aUuTZGkK9iSUb5/Tj boorfF1pkRrTxhP9tGbcafxkWPDtTkXKYZ3VXyQafga1w+9UfUWLO0LsOIpMnYQd1L0w0 dQ+kX49aNRho4UG8nPypYhQwLOC5Ni0Tf/CEsMMCW3S+AaF88Km8N5oUs/Ehq/aLMPQ==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790181975; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=gkftoKLMiM7wbJ3HdtlfIe8Jz/C3kXwZBYmMjPZpfbA=; b=Ri3yC5RLMjZbGcgGUqihHR+XH0LSvQkvJdBrLDqKKij4aIsvWiiFphMpj9aAagqd40OB OYPC3ZhymkRQmNAan6J5i/3n+TPnaWYBeSKhHGNFXOpbkQJLam257ONWBatFydkvrEeAt moGVWFWKAix4mrKxgTQxuT1oXFQUnux6/dIk8PUWBtDElzvqHn7NNrkMzWTY7GWLD1sy0 +3w8AxCbv8y5pVPsJ6ixdGg/YY2as4Sq1p/69wq6JNOmDOT+uaPbMtgcEE3KXhoHmfhgL cdhzXIGIrUTAzlUJ2Onla3D7uNeXtVtIvLWIH4cYjC6TjvtH6QpyAA3bLpmolXqW8YQ==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790185225; b=c6g/iJAGfPABmmgWiKptRE9RVvmFFHl/HZFY+E8it9OZqUlxrzTTEgQ6HoGhG+RNQcEM 9jutpoY0OkbUkF8iPeNw1MKOfTC4QKdyCTJaT0/IAootnTjyCnnA6pBcoD9oN8RRzV357 iNKgtDX23fh0JWpFgA12MpYNUQUwonwEOCL1FpeAeHeY6+MFnaJ47S1Xbdp9kydBDjBci MTzTszS06xxJiR5vcywDTVyyTZQVUdvs44gT4OzUpcBWd4zRgEPClA1E43ovMubhARzYO nFuzKSSYrLK6RumTwDgL/N6Yq77dsW9bU3xl5gasiXex74jrN1b0BsiSQWYMn4PUCVw==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790181975; b=WQw5LuW0kT1VchwXIRH8mAnOt39mIFjG5t7QnuXmWQ759efyelhv2hGliiyiPChOha0t D5jIWFGH5V/a2+44kDFyz8siCdCxAnbStfXU5OMSRQDxdPUBtXRKx1nmoo23S4DlW0p7D FZ2g06+QczTliqwkjoCfa1N/QS5fceD0ygk4eMMCHGd8sGOxhn55eDvCRUA9nZaW+ejeG tGr6snG9Jq+g5G+qALnmViK9PG4v6trySq+mNHtv4ALwNMOhzBQY4wLdWrucELyZ7xuRm 9jkig9zuHVu36OEi2+KyGgKWY5cncX4EBQQtstwjLZ4DGzhY5IxV8VLyiIaXfm5+pkA==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/7ZUGQCDHZXVXLKVBXE4COGYXQZDJKMTS/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=g8rjhsht; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=X4nY5LiN; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=SM6vSk6l; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-165

Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Less critical* 8 ∕ 25
AC:Complex/A:User/CI:Some/II:None/E:Theoretical/TD:Uncommon [2]
Vulnerability: Access bypass

Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96369
Description: 
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data.

When Webform is used with JSON:API enabled, submissions may be cached without
varying correctly by the authenticated user. If a webform is configured so
that authenticated users can view their own submissions, a request to the
JSON:API webform submission collection can return a cached response generated
for a different user.

This can allow an authenticated user to view another user's webform
submission data through the JSON:API collection endpoint.

This vulnerability is mitigated by the fact that JSON:API must be enabled,
the affected webform must expose submissions through JSON:API, and the
attacker must have an account with permission to view their own submissions
for the affected webform.

Solution: 
Install the latest version:

* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].

Reported By: 
* Giuseppe (giuseppe87) [5]

Fixed By: 
* Damien McKenna (damienmckenna) [6] of the Drupal Security Team
* Jacob Rockowitz (jrockowitz) [7]
* Lee Rowlands (larowlan) [8] of the Drupal Security Team

Coordinated By: 
* Swan Kalata (akalata) [9] of the Drupal Security Team
* Bram Driesen (bramdriesen) [10] of the Drupal Security Team
* Greg Knaddison (greggles) [11] of the Drupal Security Team
* Jacob Rockowitz (jrockowitz) [12]
* Juraj Nemec (poker10) [13] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [14]

[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/giuseppe87
[6] https://www.drupal.org/u/damienmckenna
[7] https://www.drupal.org/u/jrockowitz
[8] https://www.drupal.org/u/larowlan
[9] https://www.drupal.org/u/akalata
[10] https://www.drupal.org/u/bramdriesen
[11] https://www.drupal.org/u/greggles
[12] https://www.drupal.org/u/jrockowitz
[13] https://www.drupal.org/u/poker10
[14] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3611229

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Webform - Less critical - Access bypass - SA-CONTRIB-2026-165, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang