PT-2026-63540 · Drupal+2 · Webform Rest+1

·

CVE-2026-16644

·

Published

2026-07-22

·

Updated

2026-08-26

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Drupal Webform REST versions 0.0.0 through 4.1.0
Description Incorrect authorization in the module allows forceful browsing. The module fails to sufficiently verify permissions for creating, viewing, and updating the parent webform when accessing REST endpoints. This issue requires the attacker to already possess permissions to use the REST resource.
Recommendations Update Drupal Webform REST to a version later than 4.1.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16644
DRUPAL-CONTRIB-2026-087

Affected Products

Webform Rest
Drupal/Webform Rest