View online: https://www.drupal.org/sa-contrib-2026-186 Project: Webform REST [1] Project machine name: webform_rest Date: 2026-September-23 Security risk: *Less critical* 9 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:Uncommon [2] Vulnerability: Access bypass Affected versions: <4.2.1 CVE IDs: CVE-2026-96391 Description: This module enables you to retrieve and submit webforms via REST. The module doesn't sufficiently check permission to webform and webform submission entities when retrieving webform elements or fields. Solution: Install the latest version: * Upgrade to Webform REST 4.2.1 [3]. The 4.1.x branch is no longer supported. Reported By: * Lauri (laurii) [4] Fixed By: * Adam Bramley (acbramley) [5] * Miguel Ferreira (miguelpamferreira) [6] Coordinated By: * Swan Kalata (akalata) [7] of the Drupal Security Team * cilefen (cilefen) [8] of the Drupal Security Team * Greg Knaddison (greggles) [9] of the Drupal Security Team * Mohit Aghera (mohit_aghera) [10], provisional member of the Drupal Security Team * Juraj Nemec (poker10) [11] of the Drupal Security Team * Jess (xjm) [12] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [13] [1] https://www.drupal.org/project/webform_rest [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/webform_rest/releases/4.2.1 [4] https://www.drupal.org/u/laurii [5] https://www.drupal.org/u/acbramley [6] https://www.drupal.org/u/miguelpamferreira [7] https://www.drupal.org/u/akalata [8] https://www.drupal.org/u/cilefen [9] https://www.drupal.org/u/greggles [10] https://www.drupal.org/u/mohit_aghera [11] https://www.drupal.org/u/poker10 [12] https://www.drupal.org/u/xjm [13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....