Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-171

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-171


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-171
  • Date: Wed, 23 Sep 2026 16:46:40 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=K86AGu1X; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=gLRAGUud; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=K86AGu1X; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=gLRAGUud; arc=none smtp.remote-ip=54.240.27.116
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 0D80D4056B
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 37DAC403A9
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790185617; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=SW7O3h7upAbPCSQqS4u5I5QymA0djFRrtvDNojboUcI=; b=Pc/EIzf2dC8EQGvUxYbCV12JBv5LUBKb7EE+vRge3gYB+ArxNonRsCZxyg2sVf2C+TtH Xa9NAhfcEdyR72cdxExVw1oFToZ6AsxsA2nQXzY428uO15fJiMkP33ihu8hA6T0h4Zp90 L+gGg7b732YokQoNGGPLe3MrzURWeI0ToUS1jMw0d9clfJvUJzrHtHmjeORaxOEv5yV6Z ELxELay77h64tKX0hC4BPlTKP2fZw/XW3aRs/YduDsxq3Xy03aabda84a5p5XMPyEtL/C BmkeogfYUF5Xr5DLASLP7sHY8WcrYv/uFm5p7DCXPE9WjEpX4/cxrsGr1JZ3sLo/KGQ==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790182001; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=b9Yr5jHab1VAsayir9E0g2L8rUL2XzCOf0u+BhVpV8k=; b=LTX/C8X+Q6cXZ5gtdoC7Fyef+p/iYRGA1w1czK1BKrg8UpWKNbxBeveDGWxbCNrYfFwX hUZXTcamoP5/UwllyOfNlKMw5ugbRc3H6ibaU6usGy73PcW5gejyOfw2mPEdZy+q2YWpL JUsm9RfUzP0t/GDEoas6KAH5Lj6Tv7B3nOn8dJ59HZGipkkGIbHGTVsjF3JscTkfCrCO3 7aQFyJIO6Wvid9InDaCHYffRjK5cCvkt0YBPsneRtBeFnkJ8YLMjy6yi7KEHptd2remoq 8KpCevEVm7D/wczqs0+oyW9k2zb4l7G0AoGFLKRiZUVk/ddWjBb7WCJ0q3ktdo7530g==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790185617; b=aqMiK0PYS12Qxn3afQ9IfULdfKBpQuJ3GdaubwC7n3tyAFPL93ABDg2w+PD1VpV/MFwE gXPe+iK1RB1vySoqvdYJ/9LwpBptx7PrYGYZL5tbzU5yNa66GGGoKaYcKHdtbQfO3FR1N LuouJZm7YszuNnfAIvkVzEsjdWSRo0XoRNDs888yJzLPBm7c1mKD9bzp6YJ+y9EEYoghU YwvMimtJyqKuDvN8I9WjYTOktM6Vu+4iMb0rsRqxakzmf1hgQlCSqsUedUv8y39i2MExF 3q+0t/LK6a4SMpfO+4U/W2tkBpRDgdH6Tqh1hBCm+fUvlJ7eUjEsFMBsjL5s1+OM7ig==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790182001; b=JK0vlJrW2NS9Xt5fvhQ9PN9A8cC7/iQAPsZytcyh1vpKflvXv8Md2RT0CPMzlETTVFY/ O8lyTeUOnHSqIacc4Fcd4BAyARBBD6dUdTjJOfW1ssJ3RoENaS/Y1w4BPp7tfsKub2do0 WceqEzbEUNSCpJ2hzzH5z8P9bea10deDi9fwl8j/fmKEgNfq/Y+bZeeQtBy4pD4ptEEVh 0YgS87EXu22tau9yZUkvTiVAZ24DRhgACxSkZoWTalrWjSR61bQ9RLhWKjS58xYxtljt/ hMCbpE0Rj/1HwMu8uu81Bd8tbwORO7Pu27SKK2v7yBNIWkGVHHXoHnlo3UPx7rzoVTA==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/ONCTJICONRNMKOFFOR6JHTRO6R5QVKDW/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=PAHuydAs; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=K86AGu1X; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=gLRAGUud; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-171

Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 14 ∕ 25
AC:Basic/A:None/CI:None/II:Some/E:Exploit/TD:Uncommon [2]
Vulnerability: Access bypass

Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96364
Description: 
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data.

The Webform Share submodule can expose a webform for embedding on another
site.

Under certain circumstances, submissions for an Ajax-enabled Webform using
Webform Share can bypass anti-spam protections.

This vulnerability is mitigated by the fact that Webform Share must be
enabled, sharing must be enabled for the affected webform, and the affected
webform must rely on compatible Form-API-based anti-spam protections such as
Honeypot or Antibot.

Solution: 
Install the latest version:

* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].

Reported By: 
* karing [5]

Fixed By: 
* Alan Dixon (adixon) [6]
* Dan Chadwick (danchadwick) [7]
* Jacob Rockowitz (jrockowitz) [8]
* Liam Morland (liam morland) [9]

Coordinated By: 
* Swan Kalata (akalata) [10] of the Drupal Security Team
* Bram Driesen (bramdriesen) [11] of the Drupal Security Team
* Damien McKenna (damienmckenna) [12] of the Drupal Security Team
* Mori Sugimoto (dokumori) [13] of the Drupal Security Team
* Juraj Nemec (poker10) [14] of the Drupal Security Team
* Jess (xjm) [15] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [16]

[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/karing
[6] https://www.drupal.org/u/adixon
[7] https://www.drupal.org/u/danchadwick
[8] https://www.drupal.org/u/jrockowitz
[9] https://www.drupal.org/u/liam-morland
[10] https://www.drupal.org/u/akalata
[11] https://www.drupal.org/u/bramdriesen
[12] https://www.drupal.org/u/damienmckenna
[13] https://www.drupal.org/u/dokumori
[14] https://www.drupal.org/u/poker10
[15] https://www.drupal.org/u/xjm
[16] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3611209

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-171, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang