PT-2026-97662 · Packagist · Drupal/Webform

CVE-2026-96370

·

Published

2026-09-23

·

Updated

2026-09-23

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module includes a Webform Submission Export/Import submodule that allows importing submission data from uploaded CSV files or remote URLs.
The submodule did not sufficiently validate access to export/import functionality. A user who could edit webform submissions and access webform results could also access the import interface, including the remote URL import path, leading to a server-side request forgery vulnerability.
Sites that do not enable the Webform Submission Export/Import submodule are not affected.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-96370
DRUPAL-CONTRIB-2026-164

Affected Products

Drupal/Webform