SA-CONTRIB-2026-165: Critical severity drupal/webform vulnerability

Published Sep 23, 2026
·
Updated

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. When Webform is used with JSON:API enabled, submissions may be cached without varying correctly by the authenticated user. If a webform is configured so that authenticated users can view their own submissions, a request to the JSON:API webform submission collection can return a cached response generated for a different user. This can allow an authenticated user to view another user's webform submission data through the JSON:API collection endpoint. This vulnerability is mitigated by the fact that JSON:API must be enabled, the affected webform must expose submissions through JSON:API, and the attacker must have an account with permission to view their own submissions for the affected webform.

Credit

Giuseppe (giuseppe87)

Affected Software

1 affected componentFixes available
drupal/webform<6.2.12, <6.3.1
6.2.126.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade drupal/webform to a version that resolves this vulnerability.

    Fixed in 6.2.12Fixed in 6.3.1

Event History

Sep 23, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software

Child vulnerabilities

Contains the following vulnerabilities.

Frequently Asked Questions

1

Who is exposed to this issue?

Sites are exposed only when JSON:API is enabled and an affected webform exposes submissions through JSON:API. The webform must also allow authenticated users to view their own submissions.

2

What does an attacker need to exploit it?

An attacker needs an authenticated account with permission to view their own submissions for the affected webform. They can then request the JSON:API webform submission collection and may receive a cached response generated for another user.

3

Are default installations affected?

The issue requires specific configuration: JSON:API must be enabled, submissions must be exposed through JSON:API, and authenticated users must be allowed to view their own submissions. The provided information does not establish whether those conditions are enabled by default.

4

How can administrators identify potentially affected webforms?

Review webforms that expose submission data through JSON:API and check whether authenticated users have permission to view their own submissions. Those webforms are potentially affected when JSON:API is enabled.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203