Improper access control in Webform - CVE-2026-96373
Published: September 25, 2026 / Updated: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected module does not sufficiently validate requested filenames when serving generated submission exports. A remote administrator can access or remove files from the configured export temporary directory that are not generated for that webform.