SA-CONTRIB-2026-174: Critical severity drupal/webform vulnerability

Published Sep 23, 2026
·
Updated

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Webform did not sufficiently guard user-specific access rules against a malformed saved configuration. Under certain site-specific conditions, an access rule intended to grant submission access only to selected user accounts could also grant access to anonymous users. This vulnerability is mitigated by the fact that the bypass depends on malformed saved access-rule configuration.

Credit

Adam Bramley (acbramley), enyug

Affected Software

1 affected componentFixes available
drupal/webform<6.2.12, <6.3.1
6.2.126.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade drupal/webform to a version that resolves this vulnerability.

    Fixed in 6.2.12Fixed in 6.3.1

Event History

Sep 23, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software

Child vulnerabilities

Contains the following vulnerabilities.

Frequently Asked Questions

1

What conditions are required for anonymous users to gain submission access?

The site must have a malformed saved access-rule configuration, and the affected rule must be intended to grant submission access only to selected user accounts. The issue occurs only under site-specific conditions involving that configuration.

2

Are sites using ordinary user-specific submission access rules necessarily affected?

No. The advisory states that exploitation depends on malformed saved access-rule configuration, so the presence of user-specific access rules alone does not establish exposure.

3

How can administrators assess whether they are exposed?

Review saved Webform access-rule configurations that restrict submission access to selected user accounts, and identify malformed configurations. Verify whether anonymous users can access submissions where those rules are expected to limit access to specific accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203