Drupal · Webform Rest · CVE-2026-16644
**Name of the Vulnerable Software and Affected Versions**
Drupal Webform REST versions 0.0.0 through 4.1.0
**Description**
Incorrect authorization in the module allows forceful browsing. The module fails to sufficiently verify permissions for creating, viewing, and updating the parent webform when accessing REST endpoints. This issue requires the attacker to already possess permissions to use the REST resource.
**Recommendations**
Update Drupal Webform REST to a version later than 4.1.0.