Webform - Moderately critical - Access bypass, Server-side request forgery - SA-CONTRIB-2026-164
View online: https://www.drupal.org/sa-contrib-2026-164 Project: Webform [1] Project machine name: webform Date: 2026-September-23 Security risk: *Moderately critical* 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2] Vulnerability: Access bypass, Server-side request forgery Affected versions: <6.2.12 || >=6.3.0 <6.3.1 CVE IDs: CVE-2026-96370 Description: The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. The module includes a Webform Submission Export/Import submodule that allows importing submission data from uploaded CSV files or remote URLs. The submodule did not sufficiently validate access to export/import functionality. A user who could edit webform submissions and access webform results could also access the import interface, including the remote URL import path, leading to a server-side request forgery vulnerability. Sites that do not enable the Webform Submission Export/Import submodule are not affected. Solution: Install the latest version: * If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3]. * If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4]. For sites that need remote imports, explicitly configure the trusted hosts in settings.php: $settings['webform_submission_export_import_csv_hosts'] = ['staging.example.com']; $settings['webform_submission_export_import_file_hosts'] = ['files.staging.example.com', '*.google.com']; Reported By: * abdo.boutanos@richemont.com [5] * chulhan park (cjfgks1230) [6] * Abdulhakeem Onipede (kism37) [7] * Marcus Johansson (marcus_johansson) [8] Fixed By: * Jacob Rockowitz (jrockowitz) [9] * Marcus Johansson (marcus_johansson) [10] Coordinated By: * Swan Kalata (akalata) [11] of the Drupal Security Team * Bram Driesen (bramdriesen) [12] of the Drupal Security Team * cilefen (cilefen) [13] of the Drupal Security Team * Damien McKenna (damienmckenna) [14] of the Drupal Security Team * Greg Knaddison (greggles) [15] of the Drupal Security Team * Drew Webber (mcdruid) [16] of the Drupal Security Team * Jess (xjm) [17] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [18] [1] https://www.drupal.org/project/webform [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/webform/releases/6.2.12 [4] https://www.drupal.org/project/webform/releases/6.3.1 [5] https://www.drupal.org/u/abdoboutanosrichemontcom [6] https://www.drupal.org/u/cjfgks1230 [7] https://www.drupal.org/u/kism37 [8] https://www.drupal.org/u/marcus_johansson [9] https://www.drupal.org/u/jrockowitz [10] https://www.drupal.org/u/marcus_johansson [11] https://www.drupal.org/u/akalata [12] https://www.drupal.org/u/bramdriesen [13] https://www.drupal.org/u/cilefen [14] https://www.drupal.org/u/damienmckenna [15] https://www.drupal.org/u/greggles [16] https://www.drupal.org/u/mcdruid [17] https://www.drupal.org/u/xjm [18] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org