it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass, Server-side request forgery - SA-CONTRIB-2026-164
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass, Server-side request forgery - SA-CONTRIB-2026-164
- Date: Wed, 23 Sep 2026 16:46:09 +0000
- Arc-authentication-results: i=2; smtp4.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp3.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=UItfR+Mh; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=IeyXT4Wd; arc=none smtp.remote-ip=54.240.27.34
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org EEFD241931
- Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org 82D196067B
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790185152; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=9jK4EwVkEDxARlJJf4sB3CGduycDILV66s7cJvGnEjM=; b=JIdDOnAHZQWEevxF8u8VkTK2ZXIJ3ea0VhnNQe6eRXmSE/DanbSmAEUZtEq54iFDzqlw rhXJ9a6BYyKkivmdZ6jMIBLcD4Ctab6PAiGOV3EB1MrnmOGFeeIDERIGigc80HCO1jXfR neVIJJmJW92JB68/moFEX4AcxngRe4IJEyBUs9N390UD6osjuWUdvMyiBXSbajyvAB8P9 l3zTb6q90Kj6f55uZbBK5JmO0pQTtQnXD9OMSs8Hm+pjv655vUT6S+zBB5njTL0m/R1Kz kOnG4JDly2Qadc1msqmjjbcJUy19NAe/yZzWfebg98GjFq701TrSnNCvD170MnGZuOQ==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790181970; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=9wxWQWSA28I7GHSni5MTwt/6AzklIeDt6CGsxZ/H5yE=; b=CXQmZNqNwO5KB0ntq6prz2eLjl8KInT3B0DdmnYCaJJyqVyPHAI06Bu9ivDUw+MGBr1s IGSnmE4nKwRsBrootSfqsImNicC6XA6FxVAkkH5uL+Qovqxt9uzqcVSSpJSVN5OSkyIWK vEEhf4up0Y/oSsfblFrJqZ3uUW6wlu/3xhbRMnMXxIW+xGu8oCOk3BlQqKN3Q+59UngO5 pYInBwetSv+hWfqKvT5lfM6QcCzqcaY6O8+qDsSDnV8HGw+TFf7/K/zOQTqhbQXjtRU4N jTMZ87pMiLiKtwt+lvgghaFBXXvCVsn6x9n5mls06D4HczjaYk4Vo9tzoUJT9JKilhg==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790185152; b=PNzS4CO+PnPEltV9t4gzBjXN9P9bLGRXTLV82VD5y+9v2KX6jd/RXCxhcgmtoYJrHct3 urjERNngTbYxnvxmd3fLorm6XY4DVWomBTV9GetdMiEy1vBYmhISNHTAhs9wHFfZvVIgU ogvjlmKVb552GfDUdHN72fouE33eMonv/Gh1kFJnNJaz73OYF4X/DnihMdWinr/S4lAQP x5H2YqJyz1jm5Yg8KxyZVBn2JjN8Epm4bbukqq9MQFgIlTJW3ZjLOQu7w/KoAC7Z4UsYa thrKAWMsSrkpaeYSNOzTqT/JCZKkFpnqDuqMdN4z3WOdCnhxM32hQqmmDaGlR62RMjQ==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790181970; b=CaEtWz0gckl1i6Q90bdT6aMPvwszLlQykW7xGe753djsva5YjjFr+eoLuEjTmU/c7qLf aR1wy+PC7UmHP4Ts92XT1BXAGFbBoCMUnqjie1Ys+x6UjfvIEIjbANHGtLJbs54Zi80CC FyjQ6u46WZea4DneemIri11VO1Z4T7STD7L/bf4gUNyyKCTFq5RpmI2yt+VJ7DnoElozE avaGBln9yok03Dbc68XZB5IQgolSHYE88X7ekuPnZa1LL8eTzN8+KQthJhHBVt4clg7/V mLpKH/zmG3uubf7bbkk8PcIogPaSwyaIQL+BhboAf65BW7QDuHCzrHTFm9wOo9fUIGA==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/QZGH4OV7FBHURX5TT3SOH5AXCCRTDBZN/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=H5+L1w+t; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=UItfR+Mh; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=IeyXT4Wd; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-164
Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Access bypass, Server-side request forgery
Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96370
Description:
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data.
The module includes a Webform Submission Export/Import submodule that allows
importing submission data from uploaded CSV files or remote URLs.
The submodule did not sufficiently validate access to export/import
functionality. A user who could edit webform submissions and access webform
results could also access the import interface, including the remote URL
import path, leading to a server-side request forgery vulnerability.
Sites that do not enable the Webform Submission Export/Import submodule are
not affected.
Solution:
Install the latest version:
* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].
For sites that need remote imports, explicitly configure the trusted hosts in
settings.php:
$settings['webform_submission_export_import_csv_hosts'] =
['staging.example.com'];
$settings['webform_submission_export_import_file_hosts'] =
['files.staging.example.com', '*.google.com'];
Reported By:
* abdo.boutanos AT richemont.com [5]
* chulhan park (cjfgks1230) [6]
* Abdulhakeem Onipede (kism37) [7]
* Marcus Johansson (marcus_johansson) [8]
Fixed By:
* Jacob Rockowitz (jrockowitz) [9]
* Marcus Johansson (marcus_johansson) [10]
Coordinated By:
* Swan Kalata (akalata) [11] of the Drupal Security Team
* Bram Driesen (bramdriesen) [12] of the Drupal Security Team
* cilefen (cilefen) [13] of the Drupal Security Team
* Damien McKenna (damienmckenna) [14] of the Drupal Security Team
* Greg Knaddison (greggles) [15] of the Drupal Security Team
* Drew Webber (mcdruid) [16] of the Drupal Security Team
* Jess (xjm) [17] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [18]
[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/abdoboutanosrichemontcom
[6] https://www.drupal.org/u/cjfgks1230
[7] https://www.drupal.org/u/kism37
[8] https://www.drupal.org/u/marcus_johansson
[9] https://www.drupal.org/u/jrockowitz
[10] https://www.drupal.org/u/marcus_johansson
[11] https://www.drupal.org/u/akalata
[12] https://www.drupal.org/u/bramdriesen
[13] https://www.drupal.org/u/cilefen
[14] https://www.drupal.org/u/damienmckenna
[15] https://www.drupal.org/u/greggles
[16] https://www.drupal.org/u/mcdruid
[17] https://www.drupal.org/u/xjm
[18] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3611233
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass, Server-side request forgery - SA-CONTRIB-2026-164, security-news, 23.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.