PT-2026-97661 · Drupal · Webform Module

CVE-2026-96369

·

Published

2026-09-23

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Drupal Webform module (affected versions not specified)
Description When the Webform module is used with JSON:API enabled, submissions may be cached without varying correctly by the authenticated user. This occurs when a webform is configured to allow authenticated users to view their own submissions, potentially causing a request to the JSON:API webform submission collection endpoint to return a cached response generated for a different user. Consequently, an authenticated user may view another user's webform submission data. Approximately 436,300 instances of Drupal were identified globally as potentially exposed. This issue requires JSON:API to be enabled, the affected webform to expose submissions through JSON:API, and the attacker to possess an account with permissions to view their own submissions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-96369
DRUPAL-CONTRIB-2026-165

Affected Products

Webform Module