BlackTree Security · Infrastructure · Automation · AI

The Form Submission Was Data Until Drupal Executed It

A field submitted through a website form should remain data. In one Drupal Webform configuration, it can cross that boundary and be evaluated as template code when the submission is rendered.

CVE-2026-96355 is among the critical Drupal contributed-project advisories published on 23 September. Drupal rates it Critical, 18 out of 25, and lists information disclosure, stored cross-site scripting and remote code execution among the possible outcomes.

The vulnerable form needs a specific custom format

The issue is not an unconditional code-execution path in every site using Webform. As Drupal explains, an affected form must use a custom multiple-value item format that contains submission-value tokens. Some impact also depends on other enabled modules or site-specific configuration.

Webform did not sufficiently exclude certain format templates from token replacement. An attacker can submit crafted data that is later interpreted as template code when a submission is rendered. The security boundary fails at rendering time, which means the dangerous event may happen after the original request and in a different user’s workflow.

Two supported branches have fixed releases

Webform branchAffected versionsFixed version
6.2Earlier than 6.2.126.2.12
6.36.3.06.3.1
Version ranges from Drupal security advisory SA-CONTRIB-2026-175.

Drupal provides no separate workaround in the advisory. The supported response is to install the latest fixed release for the branch in use. The bulletin labels exploit availability as theoretical, and the reviewed sources do not establish malicious exploitation or a public working exploit for this vulnerability.

  • Inventory Drupal sites using the Webform contributed module and record the exact installed branch and version.
  • Update 6.2 installations to 6.2.12 and 6.3 installations to 6.3.1.
  • Search configuration for custom multiple-value item formats that include submission-value tokens.
  • Identify where affected submissions are rendered, exported, emailed or reviewed, including administrative workflows.
  • Review recent module, theme and form-configuration changes made by privileged users.
  • After updating, clear relevant caches and verify the running package version rather than relying only on the deployment job.

The same Drupal release window contains many additional contributed-module advisories with different prerequisites and impacts. Coverage of CVE-2026-96355 should not be read as evidence that those separate issues are fixed unless their affected modules and release notes have also been reviewed.

This flaw is consequential because it turns an expected public input channel into a possible execution path. The configuration condition narrows the exposed population, but it also makes generic perimeter scanning unreliable. Owners need package inventory and form-level configuration evidence.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *