PT-2026-97661 · Drupal · Webform Module
CVE-2026-96369
·
Published
2026-09-23
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Drupal Webform module (affected versions not specified)
Description
When the Webform module is used with JSON:API enabled, submissions may be cached without varying correctly by the authenticated user. This occurs when a webform is configured to allow authenticated users to view their own submissions, potentially causing a request to the JSON:API webform submission collection endpoint to return a cached response generated for a different user. Consequently, an authenticated user may view another user's webform submission data. Approximately 436,300 instances of Drupal were identified globally as potentially exposed. This issue requires JSON:API to be enabled, the affected webform to expose submissions through JSON:API, and the attacker to possess an account with permissions to view their own submissions.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webform Module