Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-169

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-169


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-169
  • Date: Wed, 23 Sep 2026 16:46:30 +0000
  • Arc-authentication-results: i=2; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=FD80cn5O; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=qooBthJX; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=FD80cn5O; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=qooBthJX; arc=none smtp.remote-ip=54.240.27.38
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 97E0184488
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 5F55080F27
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790185457; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=wGk+P7yBqYL1qejR0IOL+gUNqg8eZohXHLMj2BeF7zg=; b=mUPIicNI0RmFq5JpiNcGv1ZOPecAImgIHmYtJ80gfS9vqVDgFq8iBUFHr5yjL0GvcYjJ 1TDQu8xBE8Y9zL5zien1lVLRd6x5L+3QX+fyHIGqrSqO7i2u7TbEPwKxldXBPDdyXp4xX pZUhk/Fuy9SYvFo3e6HiXIJVX1DdC4V90eQ28J1iCveWMrpiNYzXU19Fo32qf48INrEq+ 5P+ZZgSlxvYTSbhS2iveFxGnWqwqUVEu9tYqCncIrJ65JsBnMq9tdT/1xetpeIGHYCC6P tFsesoEXZJY58nj0o58bBlc7Cqouw6oi1Mu5rhkymYHtpZHwsutzR4jqlTp2LAzykVA==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790181991; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=IVpS+aH0yH4/QK9QBHLLtQau7IPejr6yMpYaNk9uioA=; b=I89YretZsR/dwokPhr+Sdlt1eEh3fKV5Cfowh1givRf4qGOj7gYsQI+0gzvVyRQr32Ow BPQ8kdihLlNfBsi4y+GR1qbssSnAYkYgtGSWNmQsZXmCjVudiD8F7PTUyOE94wgUc8YYI SGkbdG3FfUlOfWteEkhfV3k55dGewPMTK07cNADp6mxcu0b8uTvlKnY6AmG3isBVf/969 RoZ4Kzqh3Wk4ryO/3IIspCFoq8uAn668tKvayPNYO6EfUvr2oYS49WEtx+ETRW8mb11ko y8Lu/xp4QxodCmcA830KwQRZA4FiEnNvS2JCvd0ipVB9XmWIWXuheZNBa5KH1aaIlOw==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790185457; b=Z1mSgqpGcOgeSSM3qJLiPruu2eXi/UKecp01dVScVpfwC3nshuJ4wM/X9FeUAQNw8w4J GwNH9Mu6TC8vKH1LSBobYoiZR40F102qma+c+E0eAxrjQO/bWfN+Nxpb5hg9D0h46EQQG Yz3VQmu0Y0OIZ7PMROmxlY5uUUG1AbBwMSLYR7w3YV6xKSPICgi9d86idmiD/zZk3eicq Cw7XbINNEsqAyhNmCMYZl0vjGD4sSoKxZXSaXyYBuHw4pcd/iFd82HZMcyHGYgMyR7faG B8DHmmElh9lYNU/YQOKu5/8G7lIhYuM+9KJuRVQBAu/p97YGxSRGqGv+wN8T5881LlA==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790181991; b=IO9B2Mv0sNJn+WnJ4fXcRl6CoufgE6OxbjXo8SFWEyapwQmpnWqbyb2LrgBiUnQI3EPx QAg//mBTT8k6YJaQLFLTm5gxyzXrA50EFde+OLe9vosgFJLDf58lREfxMI/IOWom6NAw4 vAdKUoif1RJJLOoaBEzvVd6A1zA3vZXuosvi4Yj2Dcau4kmJE0ecGmyN8kF9ZXRFhzevz Xf9ZrM3J6p6WztS0sjv1sLc6YMI6t/F3G7Giv96l0zo/CrkLIR7h6PlINFd5DwM/Pr/jK oDjv7PnnJfWe0fgLh2ZPpxS5ma7wwRsl8HbJcEnHXuQSgk0g3RT6LpNZw/iUDmoLYUA==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/KCX3GZTFUNWMMTFTJTLGFFBFXGFKVHKT/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=EwiliwdU; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=FD80cn5O; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=qooBthJX; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-169

Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 12 ∕ 25
AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:Default [2]
Vulnerability: Access bypass

Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96366
Description: 
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data.

Site builders may also configure handlers for processing submissions,
including email handlers that may include uploaded files as attachments.

In affected configurations, Webform did not sufficiently validate a managed
file upload element when processing a new submission. A user with access to
submit a vulnerable webform could potentially access other managed files they
were not authorized to view.

This vulnerability is mitigated by the fact that a site must have a Webform
with a managed file upload element and a configuration that exposes submitted
files, such as allowing users to view their own webform submissions or
sending uploads as email attachments.

Solution: 
Install the latest version:

* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].

Reported By: 
* Sandro Kneubühl (blackpharao) [5]
* omidsec [6]

Fixed By: 
* Jacob Rockowitz (jrockowitz) [7]

Coordinated By: 
* Swan Kalata (akalata) [8] of the Drupal Security Team
* Bram Driesen (bramdriesen) [9] of the Drupal Security Team
* cilefen (cilefen) [10] of the Drupal Security Team
* Damien McKenna (damienmckenna) [11] of the Drupal Security Team
* Heine Deelstra (heine) [12] of the Drupal Security Team
* Drew Webber (mcdruid) [13] of the Drupal Security Team
* Mohit Aghera (mohit_aghera) [14] provisional member of the Drupal Security
Team
* Juraj Nemec (poker10) [15] of the Drupal Security Team
* Jess (xjm) [16] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [17]

[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/blackpharao
[6] https://www.drupal.org/u/omidsec
[7] https://www.drupal.org/u/jrockowitz
[8] https://www.drupal.org/u/akalata
[9] https://www.drupal.org/u/bramdriesen
[10] https://www.drupal.org/u/cilefen
[11] https://www.drupal.org/u/damienmckenna
[12] https://www.drupal.org/u/heine
[13] https://www.drupal.org/u/mcdruid
[14] https://www.drupal.org/u/mohit_aghera
[15] https://www.drupal.org/u/poker10
[16] https://www.drupal.org/u/xjm
[17] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3611218

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-169, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang