Improper access control in Webform - CVE-2026-96398
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected module does not sufficiently restrict access to certain submission view modes. A remote user can access a more permissive view mode and see fields that would otherwise be restricted.