CVE-2026-96363 Affects Webform Submodule, Not Drupal Core, Experts Clarify
A Drupal security advisory (SA-CONTRIB-2026-161), published on 23 September 2026, identifies CVE-2026-96363 as a vulnerability in Webform Entity Print, a submodule bundled within the contributed Webform project, not in Drupal core itself. The submodule is disabled by default, meaning sites can run an affected Webform version without exposing the vulnerable code path unless the submodule is explicitly enabled. Only sites running Webform Entity Print on an affected Webform branch with specific authoring permissions assigned to user roles are considered at risk. Administrators are advised to update Webform to version 6.2.12 or 6.3.1, or disable the submodule entirely if it is not in use. A ZoomEye scan on 27 September 2026 found no indexed assets flagged under this CVE, though that result reflects a point-in-time index query and does not confirm that all sites are safe.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in